📦 Enterprise Server

by Github

🔍 What is Enterprise Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-0573

CRITICAL CVSS 9.0 Feb 18, 2026

An authenticated attacker on GitHub Enterprise Server could exploit an insecure URL redirect in the repository_pages API to leak privileged JWT tokens. This could lead to remote code execution by usin...

CVE-2025-11892

CRITICAL CVSS 9.6 Nov 10, 2025

This DOM-based XSS vulnerability in GitHub Enterprise Server allows attackers to execute malicious scripts when users click crafted links in Issues search label filters. It affects all GitHub Enterpri...

CVE-2024-10007

CRITICAL CVSS 9.1 Nov 7, 2024

This CVE describes a path collision vulnerability in GitHub Enterprise Server that allows container escape and arbitrary code execution with root privileges. It affects all versions prior to 3.15 and ...

CVE-2024-9487

CRITICAL CVSS 9.1 Oct 10, 2024

This vulnerability allows attackers to bypass SAML SSO authentication in GitHub Enterprise Server by exploiting improper cryptographic signature verification. Attackers can provision unauthorized user...

CVE-2024-6800

CRITICAL CVSS 9.8 Aug 20, 2024

An XML signature wrapping vulnerability in GitHub Enterprise Server's SAML authentication allows attackers with network access to forge SAML responses and gain administrator access without authenticat...

CVE-2024-4985

CRITICAL CVSS 9.8 May 20, 2024

This CVE describes an authentication bypass vulnerability in GitHub Enterprise Server when using SAML SSO with encrypted assertions. Attackers can forge SAML responses to create or access site adminis...

CVE-2024-2443

CRITICAL CVSS 9.1 Mar 20, 2024

A command injection vulnerability in GitHub Enterprise Server allows attackers with editor role access to the Management Console to execute arbitrary commands and gain admin SSH access to the applianc...

CVE-2024-1369

CRITICAL CVSS 9.1 Feb 13, 2024

A command injection vulnerability in GitHub Enterprise Server allows attackers with editor role access to the Management Console to gain admin SSH access to the appliance. This occurs when setting use...

CVE-2024-1374

CRITICAL CVSS 9.1 Feb 13, 2024

A command injection vulnerability in GitHub Enterprise Server allows authenticated users with editor role in the Management Console to execute arbitrary commands and gain admin SSH access when configu...

CVE-2024-1355

CRITICAL CVSS 9.1 Feb 13, 2024

A command injection vulnerability in GitHub Enterprise Server allows attackers with editor role access to the Management Console to execute arbitrary commands and gain admin SSH access via the actions...

CVE-2025-11578

HIGH CVSS 7.2 Nov 10, 2025

This CVE describes a privilege escalation vulnerability in GitHub Enterprise Server where authenticated enterprise administrators could gain root SSH access by exploiting symlink escape in pre-receive...

CVE-2025-3246

HIGH CVSS 7.6 Apr 17, 2025

A cross-site scripting vulnerability in GitHub Enterprise Server allows attackers to inject malicious scripts into math blocks using $$..$$ delimiters. This affects organizations running GitHub Enterp...

CVE-2024-10001

HIGH CVSS 7.1 Jan 29, 2025

A code injection vulnerability in GitHub Enterprise Server allows attackers to inject malicious code via the identity property in message handling, enabling DOM manipulation and sensitive data exfiltr...

CVE-2025-23369

HIGH CVSS 8.8 Jan 21, 2025

This vulnerability allows unauthorized internal users to spoof cryptographic signatures in GitHub Enterprise Server, potentially bypassing authentication mechanisms. It affects organizations using SAM...

CVE-2024-5795

HIGH CVSS 7.7 Jul 16, 2024

This CVE describes a Denial of Service vulnerability in GitHub Enterprise Server where an attacker can send a large payload to the Git server, causing unbounded resource exhaustion. This affects all o...

CVE-2024-5746

HIGH CVSS 7.6 Jun 20, 2024

A Server-Side Request Forgery vulnerability in GitHub Enterprise Server allows authenticated site administrators to execute arbitrary code on the server instance. This affects all GitHub Enterprise Se...

CVE-2024-3646

HIGH CVSS 8.0 Apr 19, 2024

A command injection vulnerability in GitHub Enterprise Server allows attackers with editor role access to the Management Console to execute arbitrary commands and gain admin SSH access when configurin...

CVE-2024-1354

HIGH CVSS 8.0 Feb 13, 2024

A command injection vulnerability in GitHub Enterprise Server allows authenticated users with editor role in the Management Console to execute arbitrary commands and gain admin SSH access via syslog-n...

CVE-2024-0200

HIGH CVSS 7.2 Jan 16, 2024

An unsafe reflection vulnerability in GitHub Enterprise Server allows authenticated organization owners to execute arbitrary methods, potentially leading to remote code execution. This affects all Git...

CVE-2023-6847

HIGH CVSS 7.5 Dec 21, 2023

This CVE describes an authentication bypass vulnerability in GitHub Enterprise Server's Private Mode. Attackers with network access can craft API requests to bypass authentication and access private r...

CVE-2023-6746

HIGH CVSS 8.1 Dec 21, 2023

CVE-2023-6746 is an information disclosure vulnerability in GitHub Enterprise Server where sensitive data is logged, potentially enabling man-in-the-middle attacks when combined with phishing. It affe...

CVE-2023-46647

HIGH CVSS 8.0 Dec 21, 2023

This vulnerability allows users with authorized access to the management console with an editor role in GitHub Enterprise Server to escalate their privileges by exploiting an endpoint used for bootstr...

CVE-2023-23761

HIGH CVSS 7.7 Apr 7, 2023

An improper authentication vulnerability in GitHub Enterprise Server allows unauthorized users to modify other users' secret gists by authenticating through an SSH certificate authority. This affects ...

CVE-2021-41598

HIGH CVSS 8.8 Jan 25, 2022

This CVE describes a UI misrepresentation vulnerability in GitHub Enterprise Server where GitHub Apps could gain additional user-level permissions without displaying them to users during repository up...

CVE-2021-22866

HIGH CVSS 8.8 May 14, 2021

This CVE describes a UI misrepresentation vulnerability in GitHub Enterprise Server where users granting authorization to GitHub Apps might unknowingly approve additional permissions not displayed dur...

CVE-2021-22864

HIGH CVSS 8.8 Mar 23, 2021

This CVE describes a remote code execution vulnerability in GitHub Enterprise Server where attackers with permission to create GitHub Pages sites could manipulate configuration options to override env...

CVE-2026-1355

MEDIUM CVSS 6.5 Feb 18, 2026

A Missing Authorization vulnerability in GitHub Enterprise Server allows authenticated attackers to upload unauthorized content to other users' repository migration exports. By exploiting the missing ...

CVE-2025-13744

MEDIUM CVSS 5.4 Jan 6, 2026

This is a cross-site scripting (XSS) vulnerability in GitHub Enterprise Server's filter/search components that allows attackers with permission to create or modify certain entities (milestones, issues...

CVE-2025-6981

MEDIUM CVSS 4.3 Jul 15, 2025

An incorrect authorization vulnerability in GitHub Enterprise Server allowed contractor accounts to read internal repository contents when the Contractors API feature was enabled. This affected all ve...

CVE-2024-8810

MEDIUM CVSS 6.5 Nov 7, 2024

A GitHub App installed in organizations could escalate permissions from read to write access without administrator approval. This vulnerability affects all GitHub Enterprise Server versions prior to 3...

CVE-2024-8770

MEDIUM CVSS 6.1 Sep 23, 2024

A Cross-Site Scripting (XSS) vulnerability in GitHub Enterprise Server's repository transfer feature allows attackers to inject malicious scripts that can steal sensitive user information through soci...

CVE-2024-5816

MEDIUM CVSS 5.3 Jul 16, 2024

A suspended GitHub App could retain unauthorized access to public repositories via scoped user access tokens in GitHub Enterprise Server. This incorrect authorization vulnerability affects all GitHub ...

CVE-2024-6336

MEDIUM CVSS 5.3 Jul 16, 2024

A security misconfiguration in GitHub Enterprise Server allowed unauthorized users to access sensitive information when an organization member changed a dependent repository from private to public. Th...