VYPR

Enterprise Server

by GitHub

CVEs (128)

  • CVE-2023-51380LowDec 21, 2023
    risk 0.18cvss 2.7epss 0.00

    An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be read with an improperly scoped token. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in version 3.7.19, 3.8.12,…

  • CVE-2026-15783MedJul 17, 2026
    risk 0.00cvss epss 0.00

    A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they did not have access to, including private repository owners and names, branch…

  • CVE-2026-15343HigJul 17, 2026
    risk 0.00cvss epss 0.00

    A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including GitHub Actions workflow files under .github/workflows/ as the…

  • CVE-2026-15007MedJul 17, 2026
    risk 0.00cvss epss 0.00

    A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When release notes were generated, the…

  • CVE-2026-14340MedJul 1, 2026
    risk 0.00cvss 5.0epss 0.00

    An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. This was possible because…

  • CVE-2026-10585MedJun 30, 2026
    risk 0.00cvss 5.4epss 0.00

    A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary JavaScript in another user's browser by injecting a crafted payload into the title of a Discussion in the Q&A category. The…

  • CVE-2026-9132MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they did not have access to. The Copilot pull request description diff summary endpoint accepted a…

  • CVE-2026-9106MedJun 30, 2026
    risk 0.00cvss 5.5epss 0.00

    A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org…

Page 7 of 7