CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

GitHub Enterprise Server < 3.22, unauthenticated SSRF via upload-endpoint path traversal exposes internal services and credentials (CVSS 4.0 = 9.2; GHSA-fwfp-h68w-2hcr)

cve · CVE-2026-9312

Coverage
1
first 2026-05-27 → last 2026-05-31
Latest activity
2026-05-27
CVE-2026-9312, GitHub Enterprise Server (< 3.22): unauthenticated SSRF via upload-endpoint path traversal…
Peak priority
high
1 high
Targets
technology
sectors: technology, finance
Sources cited
2
2 hosts

Action items (1)

Do-now tasks recorded on the entries about CVE-2026-9312, newest first. Check the date before acting on an older one.

  • Patch on-prem GitHub Enterprise Server below 3.22 (CVE-2026-9312, pre-auth SSRF reaching internal credentials), apply the relevant fixed release (3.16.20 / 3.17.17 / 3.18.11 / 3.19.8 / 3.20.4 / 3.21.1); until patched, restrict the management/upload surface at the network layer and hunt upload-endpoint logs for ../ / %2e%2e%2f traversal.
    2026-05-27CVE-2026-9312

Story timeline

  1. 2026-05-27CVE-2026-9312, GitHub Enterprise Server (< 3.22): unauthenticated SSRF via upload-endpoint path traversal exposes internal services and credentials
    trending-vulnerabilities
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-05-27/cve-2026-9312-github-enterprise-server-3-22-unauthenticated · ATT&CK page ↗

Entries about GitHub Enterprise Server < 3.22, unauthenticated SSRF via upload-endpoint path traversal exposes internal services and credentials (CVSS 4.0 = 9.2; GHSA-fwfp-h68w-2hcr) (1)

2026-05-27 · view entry permalink →

CVE-2026-9312, GitHub Enterprise Server (< 3.22): unauthenticated SSRF via upload-endpoint path traversal exposes internal services and credentials

An unauthenticated attacker can inject path-traversal content into the request parameters of a GitHub Enterprise Server upload endpoint; insufficient input validation lets the crafted request bypass the intended upload flow and redirect internal API calls to arbitrary internal services, potentially reading internal service responses and exposing sensitive credentials such as GitHub App tokens, service-account keys and internal API secrets (ENISA EUVD EUVD-2026-32027, 2026-05-27). The flaw (also tracked as GHSA-fwfp-h68w-2hcr, CVSS 4.0 = 9.2) was reported through the GitHub Bug Bounty program and affects all GHES releases prior to 3.22; fixes ship in 3.16.20, 3.17.17, 3.18.11, 3.19.8, 3.20.4 and 3.21.1 (GitHub Security Advisory GHSA-fwfp-h68w-2hcr). EPSS is 0.0 and no in-the-wild exploitation is reported, but on-prem GHES is common in Swiss financial-sector and EU large-enterprise development estates, and an SSRF that reaches internal credential stores is a direct foothold for lateral movement (T1190 Exploit Public-Facing Application). Patch to the relevant fixed release; until patched, restrict who can reach the GHES management/upload surface at the network layer and hunt server access logs for upload-endpoint requests carrying ../ / %2e%2e%2f traversal sequences.

vulnerability27 May 05:00Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Vulns1

Source distribution

  • euvd.enisa.europa.eu1 (50%)
  • github.com1 (50%)