CVE-2026-9312

HIGH

CVSS v3.1: 8.2 · EPSS: 0.0006 (20.3 percentile)

NetworkNo privilegesNo user interactionSSRFVendor advisory ref

Source data as of:

At a glance

Severity
HIGH
CVSS
8.2 v3.1 · NVD
EPSS
0.0006 (20.3 percentile) · FIRST.org
CISA KEV
No
Type
SSRF · NVD CWE
Attack conditions (CVSS vector)
NetworkNo privilegesNo user interaction · Source: NVD Vector
Affected vendors
github
Published
2026-05-27 · Modified: 2026-06-02

CVSS / EPSS / KEV

CVSS v3.1 8.2 / 10 HIGH Source: NVD
CVSS v4.0 9.2 / 10 CRITICAL Source: NVD
EPSS 0.0006 20.3 percentile Source: FIRST.org
CISA KEV No Source: CISA

Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources

Description

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal content into request parameters, an attacker could bypass the intended request flow and redirect internal API calls, potentially accessing internal services and exposing sensitive credentials. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.16.20, 3.17.17, 3.18.11, 3.19.8, 3.20.4, and 3.21.1. This vulnerability was reported via the GitHub Bug Bounty program.

Record details

CVE ID
CVE-2026-9312
CVSS (v3.1)
8.2 (HIGH)
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Exploitability subscore
3.9
Impact subscore
4.2
EPSS
0.0006 (20.3 percentile) — 2026-06-03
CISA KEV
No
Weakness (CWE)
CWE-918
Affected vendors
github
Affected configurations (CPE)
6
Published
2026-05-27
Modified
2026-06-02
Status
Analyzed

References

Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.