logo

GitHub Enterprise Server 3.20.3 Addresses Critical Security Flaws

ID: 747bec77-d90e-56aa-87e0-bb8deee057e3

STIX ID: report--747bec77-d90e-56aa-87e0-bb8deee057e3

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-27

Date Updated: 2026-07-21

Author: Divya

...
...

GitHub released Enterprise Server 3.20.3 to fix multiple critical and high-severity vulnerabilities — notably a pre-auth SSRF (CVE-2026-9312) allowing requests to internal services, kernel "Dirty Frag" local privilege escalation flaws (CVE-2026-43284/CVE-2026-43500), and a timing side-channel combined with SSRF that could expose environment variables via Packages (CVE-2026-8606). The release requires administrators to rotate GPG signing keys before updating, includes removal of the vulnerable package endpoint, a provided key-rotation script, and recommendations to restrict network access, reapply firewall rules after upgrade, and validate cluster/monitoring configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.