
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0573 is a URL redirection vulnerability (open redirect) in GitHub Enterprise Server (GHES) that allows authenticated attackers to leak privileged authorization tokens by redirecting API requests to attacker-controlled domains. The repository_pages API insecurely follows HTTP redirects when fetching artifact URLs while preserving the Authorization header containing a privileged JWT (Actions.ManageOrgs), enabling token exfiltration and potential remote code execution. All versions of GHES prior to the patched releases are affected, including versions across the 3.14–3.19 branches. It carries a CVSS v3.1 base score of 9.0 (Critical) and a CVSS v4.0 base score of 7.6 (High) (Feedly, GHES 3.14 Release Notes). The vulnerability was disclosed on February 18, 2026, and was reported via the GitHub Bug Bounty program.
The root cause is classified as CWE-601 (URL Redirection to Untrusted Site / 'Open Redirect'). The repository_pages API endpoint in GHES insecurely follows HTTP redirects when fetching artifact URLs without stripping or validating the Authorization header before forwarding it to the redirect destination. An authenticated user can craft or exploit a legacy redirect pointing to an attacker-controlled domain; when the GHES server follows this redirect, it forwards the Authorization header containing the Actions.ManageOrgs JWT to the external server. Exploitation requires the attacker to have authenticated access to the target GHES instance and the ability to trigger or influence a redirect to an attacker-controlled domain (Feedly, GHES 3.14 Release Notes).
Successful exploitation allows an authenticated attacker to exfiltrate the Actions.ManageOrgs JWT token, a highly privileged credential used internally by GitHub Actions. With this token, an attacker could potentially achieve remote code execution within the GitHub Enterprise environment and gain unauthorized control over organizational resources. The confidentiality, integrity, and availability impacts are all rated HIGH under CVSS v3.1, with a changed scope indicating that the impact extends beyond the vulnerable component itself (Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.099%, indicating a low current probability of exploitation in the wild. Exploitation requires authenticated access to the target GHES instance and the ability to leverage a legacy redirect to an attacker-controlled domain, which somewhat limits the attack surface (Feedly).
repository_pages API endpoint responsible for fetching artifact URLs, which insecurely follows HTTP redirects.Authorization header.repository_pages API to issue an HTTP request that redirects to the attacker-controlled domain (e.g., by manipulating artifact URL parameters or exploiting a known redirect path).Authorization header containing the Actions.ManageOrgs JWT to the attacker's server; capture this token from the server logs.Actions.ManageOrgs JWT to authenticate against internal GHES services, potentially achieving remote code execution or unauthorized organizational management (Feedly, GHES 3.14 Release Notes).repository_pages API or Actions-related services; requests to external domains carrying an Authorization: Bearer <JWT> header.repository_pages artifact URL endpoint followed by HTTP 3xx redirect responses to external domains; audit log entries for API calls involving artifact URL fetching with unusual redirect destinations.Actions.ManageOrgs JWT from IP addresses or user agents inconsistent with normal GHES internal service behavior; token activity originating from external or unknown IP addresses.GitHub has released patched versions addressing CVE-2026-0573: 3.14.22, 3.15.17, 3.16.13, 3.17.10, 3.18.4, and 3.19.2 (GHES 3.14 Release Notes, GHES 3.15 Release Notes, GHES 3.16 Release Notes, GHES 3.17 Release Notes, GHES 3.18 Release Notes). All versions prior to 3.14.22 are also vulnerable. If immediate patching is not possible, administrators should restrict API access to trusted users, monitor API logs for suspicious redirect patterns, and consider network-level controls to block outbound requests from GHES to unexpected external domains (Feedly).
The vulnerability was reported via the GitHub Bug Bounty program and disclosed alongside other security fixes in the February 2026 GHES patch releases (GHES 3.14 Release Notes). Coverage was picked up by threat intelligence aggregators including CVEFeed and Infinitsec shortly after disclosure, and the vulnerability was noted on Bluesky by The Hacker Wire (Feedly). No significant independent researcher commentary or broad media coverage has been identified beyond standard vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."