BlackTreeCVE IntelligenceOfficial source evidencedocs.github.comVersioned article
Official source article · docs.github.com
Release notes - GitHub Enterprise Server 3.15 Docs
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherdocs.github.com
Article IDNo stable ID in source URL
Verified snapshot28 Sept 2026, 14:38 UTC
Linked CVEs18
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-5845Improper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise Server
- CVE-2026-3307Authorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewers
- CVE-2026-5512Improper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via mobile upload policy API
- CVE-2026-5921Server-Side Request Forgery in GitHub Enterprise Server allowed extraction of sensitive environment variables via timing side-channel attack
- CVE-2026-4296Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypass
- CVE-2026-3306Improper authorization in GitHub Projects allows modification of issue and pull request metadata without repository write access
- CVE-2026-1355Missing Authorization Check in GitHub Enterprise Server Allows Unauthorized Uploads to Repository Migration Exports
- CVE-2026-0573Improper Handling of HTTP Redirects vulnerability was identified in GitHub Enterprise Server that allowed leaking of authorization token and enabled remote code execution
- CVE-2025-13744Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server that allowed rendering of malicious HTML
- CVE-2025-14046Insufficient HTML Sanitization Allows User-Controlled DOM Elements to Overwrite Server-Initialized Data Islands and Trigger Unintended Server-Side POST Requests
- CVE-2025-11578Pre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege Escalation
- CVE-2025-11892DOM-based Cross-Site Scripting was identified in GitHub Enterprise Server Issues search allows privilege escalation and unauthorized workflow triggers
- CVE-2025-8447Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed read-only access
- CVE-2025-6981Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized read-only access
- CVE-2025-3509Pre-Receive Hook Remote Code Execution vulnerability was identified in GitHub Enterprise Server that allowing Privilege Escalation
- CVE-2025-3124Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed unauthorized access to private repository names
- CVE-2025-23369Improper Verification of Cryptographic Signature in GitHub Enterprise Server Allows Signature Spoofing by Improper Validation
- CVE-2024-10001Code Injection Vulnerability in GitHub Enterprise Server Allows Arbitrary Code Execution via Message Handling
Source and provenance
Original title: Release notes - GitHub Enterprise Server 3.15 Docs. Captured 28 Sept 2026, 14:38 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗