CVE Tools

Enterprise Server

175 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Enterprise Server, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Enterprise Server CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Enterprise Server CVEs per month
MonthCVEs
2024-102
2024-113
2024-120
2025-012
2025-020
2025-030
2025-043
2025-050
2025-060
2025-072
2025-082
2025-090
2025-100
2025-112
2025-121
2026-011
2026-023
2026-034
2026-045
2026-056
2026-063
2026-074
2026-082
2026-096

Severity

How the 175 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical2515%
  • High5130%
  • Medium8852%
  • Low53%

Latest CVEs

The 15 most recently published vulnerabilities affecting Enterprise Server.

  1. CVE-2026-75101Authorization bypass vulnerability in GitHub Enterprise Server allowed reading of private pull request diffs and patches via repository name collision—
  2. CVE-2026-77912Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipeline—
  3. CVE-2026-77987GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery—
  4. CVE-2026-76851Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access from pre-receive hooks to internal services8.8
  5. CVE-2026-19118Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution7.5
  6. CVE-2026-18730Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer token7.4
  7. CVE-2026-15996Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters7.5
  8. CVE-2026-17556Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header9.1
  9. CVE-2026-15783Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites—
  10. CVE-2026-15343Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths—
  11. CVE-2026-15007Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration—
  12. CVE-2026-14340An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories5.0
  13. CVE-2026-10585Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed arbitrary JavaScript execution via crafted Discussion titles in the Q&A category5.4
  14. CVE-2026-9132Missing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via the Copilot pull request diff summary endpoint6.5
  15. CVE-2026-9106UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen5.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store