
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-17556 is a path traversal vulnerability in GitHub Enterprise Server (GHES) that allows an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory containing Git LFS objects, release assets, attachments, and avatars. The vulnerability affects all GHES versions prior to 3.22, specifically versions 3.17.0–3.17.18, 3.18.0–3.18.12, 3.19.0–3.19.9, 3.20.0–3.20.5, and 3.21.0–3.21.3. It was disclosed on August 5, 2026, and reported via the GitHub Bug Bounty program. The vulnerability carries a CVSS v4.0 base score of 8.8 (High) (GitHub Advisory, GHES 3.21 Release Notes).
The root cause is improper limitation of a pathname to a restricted directory (CWE-22). The X-GitHub-Request-Id HTTP request header is used without sanitization as a filesystem path segment for the upload buffer directory. By supplying a path traversal sequence (e.g., ../../) in this header, an attacker can redirect the upload buffer to an arbitrary filesystem path. A deferred cleanup routine then recursively deletes the traversed target directory. Exploitation requires only network reachability to the GHES instance, no authentication, and succeeds even when private mode is enabled (GitHub Advisory, GHES 3.17 Release Notes).
Successful exploitation allows an unauthenticated, remote attacker to recursively delete arbitrary files and directories on the GHES instance, with the most severe outcome being the complete destruction of the user storage directory. This results in permanent loss of Git LFS objects, release assets, file attachments, and user avatars, causing significant availability and integrity impact. There is no confidentiality impact (data is deleted, not exfiltrated), but the destruction of critical repository data could severely disrupt enterprise software development operations and may require restoration from backups (GitHub Advisory, GHES 3.20 Release Notes).
As of the disclosure date (August 5, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability is highly exploitable in principle — it requires no authentication, no user interaction, and no special preconditions beyond network access to the GHES instance. The EPSS score is reported as 0.0 at time of publication, and the vulnerability has not been added to the CISA KEV catalog based on available information. No threat actor attribution has been reported.
X-GitHub-Request-Id header, embedding a path traversal payload such as ../../target/directory in the header value.../, %2e%2e%2f) in the X-GitHub-Request-Id header.X-GitHub-Request-Id header values; application logs recording unexpected directory creation or deletion events outside normal upload buffer paths.GitHub has released patched versions addressing this vulnerability: 3.21.4, 3.20.6, 3.19.10, 3.18.13, and 3.17.19, all released on August 5, 2026. Administrators should upgrade to the appropriate patched version immediately. As a temporary workaround if immediate patching is not possible, implement network access controls (firewall rules or network segmentation) to restrict unauthenticated network access to the GHES instance, reducing the attack surface (GHES 3.21 Release Notes, GHES 3.17 Release Notes).
The vulnerability was reported through GitHub's Bug Bounty program and disclosed alongside the patched releases on August 5, 2026. GitHub's official release notes across all affected version branches (3.17–3.21) consistently classify this as a HIGH severity security fix. No notable independent researcher commentary or significant social media discussion has been identified at the time of this report.
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"