VYPR

Enterprise Server

by GitHub

CVEs (131)

  • CVE-2025-8447LowAug 26, 2025
    risk 0.20cvss 3.1epss 0.00

    An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another repository by creating a diff between the repositories. To exploit this vulnerability, an attacker…

  • CVE-2026-3307LowApr 21, 2026
    risk 0.18cvss 2.7epss 0.00

    An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin access on one repository to modify the secret scanning push protection delegated bypass reviewer list on another repository by manipulating the owner_id parameter…

  • CVE-2024-8263LowSep 23, 2024
    risk 0.18cvss 2.7epss 0.00

    An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9,…

  • CVE-2023-51380LowDec 21, 2023
    risk 0.18cvss 2.7epss 0.00

    An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be read with an improperly scoped token. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.19, 3.8.12,…

  • CVE-2026-15783MedJul 17, 2026
    risk 0.00cvss —epss 0.00

    A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they did not have access to, including private repository owners and names, branch…

  • CVE-2026-15343HigJul 17, 2026
    risk 0.00cvss —epss 0.01

    A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including GitHub Actions workflow files under .github/workflows/ as the…

  • CVE-2026-15007MedJul 17, 2026
    risk 0.00cvss —epss 0.01

    A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When release notes were generated, the…

  • CVE-2026-14340MedJul 1, 2026
    risk 0.00cvss 5.0epss 0.00

    An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. This was possible because…

  • CVE-2026-10585MedJun 30, 2026
    risk 0.00cvss 5.4epss 0.00

    A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary JavaScript in another user's browser by injecting a crafted payload into the title of a Discussion in the Q&A category. The…

  • CVE-2026-9132MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they did not have access to. The Copilot pull request description diff summary endpoint accepted a…

  • CVE-2026-9106MedJun 30, 2026
    risk 0.00cvss 5.5epss 0.00

    A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org…

Page 7 of 7