
PEACH
Un cadre d’isolation des locataires
CVE-2026-17556 is a path traversal vulnerability in GitHub Enterprise Server (GHES) that allows an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory containing Git LFS objects, release assets, attachments, and avatars. The vulnerability affects all GHES versions prior to 3.22, specifically versions 3.17.0–3.17.18, 3.18.0–3.18.12, 3.19.0–3.19.9, 3.20.0–3.20.5, and 3.21.0–3.21.3. It was disclosed on August 5, 2026, and reported via the GitHub Bug Bounty program. The vulnerability carries a CVSS v4.0 base score of 8.8 (High) (GitHub Advisory, GHES 3.21 Release Notes).
The root cause is improper limitation of a pathname to a restricted directory (CWE-22). The X-GitHub-Request-Id HTTP request header is used without sanitization as a filesystem path segment for the upload buffer directory. By supplying a path traversal sequence (e.g., ../../) in this header, an attacker can redirect the upload buffer to an arbitrary filesystem path. A deferred cleanup routine then recursively deletes the traversed target directory. Exploitation requires only network reachability to the GHES instance, no authentication, and succeeds even when private mode is enabled (GitHub Advisory, GHES 3.17 Release Notes).
Successful exploitation allows an unauthenticated, remote attacker to recursively delete arbitrary files and directories on the GHES instance, with the most severe outcome being the complete destruction of the user storage directory. This results in permanent loss of Git LFS objects, release assets, file attachments, and user avatars, causing significant availability and integrity impact. There is no confidentiality impact (data is deleted, not exfiltrated), but the destruction of critical repository data could severely disrupt enterprise software development operations and may require restoration from backups (GitHub Advisory, GHES 3.20 Release Notes).
As of the disclosure date (August 5, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability is highly exploitable in principle — it requires no authentication, no user interaction, and no special preconditions beyond network access to the GHES instance. The EPSS score is reported as 0.0 at time of publication, and the vulnerability has not been added to the CISA KEV catalog based on available information. No threat actor attribution has been reported.
X-GitHub-Request-Id header, embedding a path traversal payload such as ../../target/directory in the header value.../, %2e%2e%2f) in the X-GitHub-Request-Id header.X-GitHub-Request-Id header values; application logs recording unexpected directory creation or deletion events outside normal upload buffer paths.GitHub has released patched versions addressing this vulnerability: 3.21.4, 3.20.6, 3.19.10, 3.18.13, and 3.17.19, all released on August 5, 2026. Administrators should upgrade to the appropriate patched version immediately. As a temporary workaround if immediate patching is not possible, implement network access controls (firewall rules or network segmentation) to restrict unauthenticated network access to the GHES instance, reducing the attack surface (GHES 3.21 Release Notes, GHES 3.17 Release Notes).
The vulnerability was reported through GitHub's Bug Bounty program and disclosed alongside the patched releases on August 5, 2026. GitHub's official release notes across all affected version branches (3.17–3.21) consistently classify this as a HIGH severity security fix. No notable independent researcher commentary or significant social media discussion has been identified at the time of this report.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."