BlackTreeCVE IntelligenceOfficial source evidencedocs.github.comVersioned article
Official source article · docs.github.com
Release notes - GitHub Enterprise Server 3.21 Docs
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherdocs.github.com
Article IDNo stable ID in source URL
Verified snapshot27 Sept 2026, 02:00 UTC
Linked CVEs6
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-19118Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution
- CVE-2026-76851Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access from pre-receive hooks to internal services
- CVE-2026-17556Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header
- CVE-2026-14340An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories
- CVE-2026-9106UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen
- CVE-2026-8606Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL Endpoint
Source and provenance
Original title: Release notes - GitHub Enterprise Server 3.21 Docs. Captured 27 Sept 2026, 02:00 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗