Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-19118
GitHub Enterprise Server vulnerability analysis and mitigation

Overview

CVE-2026-19118 is a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in GitHub Enterprise Server (GHES) that enables remote code execution by authenticated users. The flaw affects all GHES versions prior to 3.22, specifically versions 3.17.0–3.17.19, 3.18.0–3.18.13, 3.19.0–3.19.10, 3.20.0–3.20.6, and 3.21.0–3.21.4. It was disclosed on September 1, 2026, and reported through the GitHub Bug Bounty program. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, GHES 3.21 Release Notes).

Technical details

The vulnerability is classified as CWE-367 (Time-of-Check Time-of-Use Race Condition). The attack exploits a window between the validation of an uploaded file and its subsequent processing: an attacker can replace the validated upload with attacker-controlled content during this interval by submitting precisely timed concurrent upload requests. Exploitation requires an authenticated user account with write access to at least one repository on the target GHES instance, and success depends on precise timing of concurrent requests — making it a high-complexity but network-accessible attack. No public proof-of-concept code has been identified (GitHub Advisory, GHES 3.17 Release Notes).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary code on the GitHub Enterprise Server instance, resulting in full compromise of confidentiality, integrity, and availability of the affected system. An attacker achieving code execution on the GHES instance could access sensitive source code, secrets, credentials, and internal data hosted on the platform, and could potentially pivot to other internal systems reachable from the server. The technical impact is rated as "total" by NVD's SSVC assessment (GitHub Advisory, GHES 3.20 Release Notes).

Exploitability

As of the disclosure date, there is no evidence of active in-the-wild exploitation and no public proof-of-concept exploit has been identified (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.0045 (0.45%), indicating a low near-term exploitation probability. Exploitation is not automatable due to the requirement for precise timing and authenticated access with repository write permissions.

Exploitation steps

  1. Obtain authenticated access: Acquire valid credentials for a GHES account with write access to at least one repository on the target instance (e.g., through phishing, credential theft, or use of a legitimately provisioned account).
  2. Identify target instance: Confirm the GHES instance is running a vulnerable version (prior to 3.17.20, 3.18.14, 3.19.11, 3.20.7, 3.21.5, or 3.22.0).
  3. Initiate a legitimate upload: Begin a file upload operation to the repository via the GHES API or web interface, triggering the server-side validation of the uploaded content.
  4. Race the validation window: Simultaneously submit a second concurrent upload request designed to replace the validated file with attacker-controlled content before the server processes the originally validated file — exploiting the TOCTOU window.
  5. Achieve code execution: If the race condition is won, the server processes the attacker-controlled content as if it were the validated upload, resulting in arbitrary code execution on the GHES instance (GitHub Advisory, GHES 3.19 Release Notes).

Indicators of compromise

  • Logs: Unusual patterns of rapid, concurrent file upload requests from the same authenticated user or IP address in GHES access logs; unexpected server-side errors or anomalies in upload processing logs around the time of suspicious activity.
  • File System: Unexpected files or scripts appearing in repository storage directories or GHES application directories that were not committed through normal Git operations.
  • Process: Unusual child processes spawned by the GHES application process (e.g., shell processes, network utilities like curl or wget) not associated with normal platform operations.
  • Network: Unexpected outbound connections from the GHES server to external or unknown IP addresses following upload activity.

Mitigation and workarounds

GitHub has released patched versions addressing CVE-2026-19118: 3.17.20, 3.18.14, 3.19.11, 3.20.7, 3.21.5, and 3.22.0 (and all later 3.22.x releases). Administrators should upgrade to the appropriate patched version for their release series as the primary remediation. As an interim measure, organizations should review and restrict repository write access to only trusted users, and monitor for suspicious concurrent upload activity. No configuration-only workaround has been published by GitHub (GHES 3.17 Release Notes, GHES 3.18 Release Notes, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related GitHub Enterprise Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-17556HIGH8.8
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesAug 05, 2026
CVE-2026-18730HIGH8.2
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 01, 2026
CVE-2026-76851HIGH7.7
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 01, 2026
CVE-2026-19118HIGH7.7
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesSep 01, 2026
CVE-2026-15996MEDIUM6.6
  • GitHub Enterprise Server logoGitHub Enterprise Server
  • cpe:2.3:a:github:enterprise_server
NoYesAug 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management