CVE-2026-0573: 
GitHub Enterprise Server vulnerability analysis and mitigation

Overview

CVE-2026-0573 is a URL redirection vulnerability (open redirect) in GitHub Enterprise Server (GHES) that allows authenticated attackers to leak privileged authorization tokens by redirecting API requests to attacker-controlled domains. The repository_pages API insecurely follows HTTP redirects when fetching artifact URLs while preserving the Authorization header containing a privileged JWT (Actions.ManageOrgs), enabling token exfiltration and potential remote code execution. All versions of GHES prior to the patched releases are affected, including versions across the 3.14–3.19 branches. It carries a CVSS v3.1 base score of 9.0 (Critical) and a CVSS v4.0 base score of 7.6 (High) (Feedly, GHES 3.14 Release Notes). The vulnerability was disclosed on February 18, 2026, and was reported via the GitHub Bug Bounty program.

Technical details

The root cause is classified as CWE-601 (URL Redirection to Untrusted Site / 'Open Redirect'). The repository_pages API endpoint in GHES insecurely follows HTTP redirects when fetching artifact URLs without stripping or validating the Authorization header before forwarding it to the redirect destination. An authenticated user can craft or exploit a legacy redirect pointing to an attacker-controlled domain; when the GHES server follows this redirect, it forwards the Authorization header containing the Actions.ManageOrgs JWT to the external server. Exploitation requires the attacker to have authenticated access to the target GHES instance and the ability to trigger or influence a redirect to an attacker-controlled domain (Feedly, GHES 3.14 Release Notes).

Impact

Successful exploitation allows an authenticated attacker to exfiltrate the Actions.ManageOrgs JWT token, a highly privileged credential used internally by GitHub Actions. With this token, an attacker could potentially achieve remote code execution within the GitHub Enterprise environment and gain unauthorized control over organizational resources. The confidentiality, integrity, and availability impacts are all rated HIGH under CVSS v3.1, with a changed scope indicating that the impact extends beyond the vulnerable component itself (Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.099%, indicating a low current probability of exploitation in the wild. Exploitation requires authenticated access to the target GHES instance and the ability to leverage a legacy redirect to an attacker-controlled domain, which somewhat limits the attack surface (Feedly).

Exploitation steps

  1. Gain authenticated access: Obtain a valid user account on the target GitHub Enterprise Server instance (low-privilege access is sufficient).
  2. Identify the vulnerable endpoint: Target the repository_pages API endpoint responsible for fetching artifact URLs, which insecurely follows HTTP redirects.
  3. Set up attacker-controlled server: Deploy an HTTP server on an attacker-controlled domain configured to log incoming HTTP request headers, particularly the Authorization header.
  4. Trigger a redirect: Craft or exploit a legacy redirect mechanism within GHES that causes the repository_pages API to issue an HTTP request that redirects to the attacker-controlled domain (e.g., by manipulating artifact URL parameters or exploiting a known redirect path).
  5. Capture the JWT: When GHES follows the redirect, it forwards the Authorization header containing the Actions.ManageOrgs JWT to the attacker's server; capture this token from the server logs.
  6. Leverage the token: Use the exfiltrated Actions.ManageOrgs JWT to authenticate against internal GHES services, potentially achieving remote code execution or unauthorized organizational management (Feedly, GHES 3.14 Release Notes).

Indicators of compromise

  • Network: Outbound HTTP/HTTPS requests from the GHES server to unexpected or external domains originating from the repository_pages API or Actions-related services; requests to external domains carrying an Authorization: Bearer <JWT> header.
  • Logs: GHES API access logs showing requests to the repository_pages artifact URL endpoint followed by HTTP 3xx redirect responses to external domains; audit log entries for API calls involving artifact URL fetching with unusual redirect destinations.
  • Tokens: Unexpected use of the Actions.ManageOrgs JWT from IP addresses or user agents inconsistent with normal GHES internal service behavior; token activity originating from external or unknown IP addresses.

Mitigation and workarounds

GitHub has released patched versions addressing CVE-2026-0573: 3.14.22, 3.15.17, 3.16.13, 3.17.10, 3.18.4, and 3.19.2 (GHES 3.14 Release Notes, GHES 3.15 Release Notes, GHES 3.16 Release Notes, GHES 3.17 Release Notes, GHES 3.18 Release Notes). All versions prior to 3.14.22 are also vulnerable. If immediate patching is not possible, administrators should restrict API access to trusted users, monitor API logs for suspicious redirect patterns, and consider network-level controls to block outbound requests from GHES to unexpected external domains (Feedly).

Community reactions

The vulnerability was reported via the GitHub Bug Bounty program and disclosed alongside other security fixes in the February 2026 GHES patch releases (GHES 3.14 Release Notes). Coverage was picked up by threat intelligence aggregators including CVEFeed and Infinitsec shortly after disclosure, and the vulnerability was noted on Bluesky by The Hacker Wire (Feedly). No significant independent researcher commentary or broad media coverage has been identified beyond standard vulnerability tracking.

Additional resources


Source: This report was generated using AI

Related GitHub Enterprise Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77987CRITICAL9.3
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 22, 2026
CVE-2026-76851HIGH7.7
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 01, 2026
CVE-2026-19118HIGH7.7
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 01, 2026
CVE-2026-77912HIGH7.4
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 22, 2026
CVE-2026-75101MEDIUM6
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management