
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19118 is a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in GitHub Enterprise Server (GHES) that enables remote code execution by authenticated users. The flaw affects all GHES versions prior to 3.22, specifically versions 3.17.0–3.17.19, 3.18.0–3.18.13, 3.19.0–3.19.10, 3.20.0–3.20.6, and 3.21.0–3.21.4. It was disclosed on September 1, 2026, and reported through the GitHub Bug Bounty program. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, GHES 3.21 Release Notes).
The vulnerability is classified as CWE-367 (Time-of-Check Time-of-Use Race Condition). The attack exploits a window between the validation of an uploaded file and its subsequent processing: an attacker can replace the validated upload with attacker-controlled content during this interval by submitting precisely timed concurrent upload requests. Exploitation requires an authenticated user account with write access to at least one repository on the target GHES instance, and success depends on precise timing of concurrent requests — making it a high-complexity but network-accessible attack. No public proof-of-concept code has been identified (GitHub Advisory, GHES 3.17 Release Notes).
Successful exploitation allows an authenticated attacker to execute arbitrary code on the GitHub Enterprise Server instance, resulting in full compromise of confidentiality, integrity, and availability of the affected system. An attacker achieving code execution on the GHES instance could access sensitive source code, secrets, credentials, and internal data hosted on the platform, and could potentially pivot to other internal systems reachable from the server. The technical impact is rated as "total" by NVD's SSVC assessment (GitHub Advisory, GHES 3.20 Release Notes).
As of the disclosure date, there is no evidence of active in-the-wild exploitation and no public proof-of-concept exploit has been identified (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.0045 (0.45%), indicating a low near-term exploitation probability. Exploitation is not automatable due to the requirement for precise timing and authenticated access with repository write permissions.
curl or wget) not associated with normal platform operations.GitHub has released patched versions addressing CVE-2026-19118: 3.17.20, 3.18.14, 3.19.11, 3.20.7, 3.21.5, and 3.22.0 (and all later 3.22.x releases). Administrators should upgrade to the appropriate patched version for their release series as the primary remediation. As an interim measure, organizations should review and restrict repository write access to only trusted users, and monitor for suspicious concurrent upload activity. No configuration-only workaround has been published by GitHub (GHES 3.17 Release Notes, GHES 3.18 Release Notes, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."