GitHub Enterprise Server 3.20.3 Addresses Critical Security Flaws
ID: 747bec77-d90e-56aa-87e0-bb8deee057e3
STIX ID: report--747bec77-d90e-56aa-87e0-bb8deee057e3
Feed Name: GBHackers
GitHub released Enterprise Server 3.20.3 to fix multiple critical and high-severity vulnerabilities — notably a pre-auth SSRF (CVE-2026-9312) allowing requests to internal services, kernel "Dirty Frag" local privilege escalation flaws (CVE-2026-43284/CVE-2026-43500), and a timing side-channel combined with SSRF that could expose environment variables via Packages (CVE-2026-8606). The release requires administrators to rotate GPG signing keys before updating, includes removal of the vulnerable package endpoint, a provided key-rotation script, and recommendations to restrict network access, reapply firewall rules after upgrade, and validate cluster/monitoring configurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
