
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-77987 is a Server-Side Request Forgery (SSRF) vulnerability in the notebook viewer component of GitHub Enterprise Server (GHES) that can lead to remote code execution on the appliance. The notebook viewer validated the scheme and host of user-supplied URLs but failed to validate the port, allowing requests to be directed to internal services on other ports of the same appliance. It affects GHES versions 3.17.0 through 3.22.0 (prior to the respective patch releases) and was disclosed on September 22, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (GitHub Advisory, GHES 3.17 Release Notes).
The root cause is an incomplete URL validation in the GHES notebook viewer (CWE-918: Server-Side Request Forgery; CWE-208: Observable Timing Discrepancy). The viewer correctly checked the scheme and host of user-supplied URLs but omitted port validation, enabling an attacker to craft a notebook viewer URL with an explicit port number to reach internal services co-located on the appliance. Although response bodies were not returned to the requester, response timing differences acted as a side-channel oracle (CAPEC-462: Cross-Domain Search Timing), allowing an attacker to extract instance secrets character by character. Those extracted secrets could then be used in a separate interaction with an internal privileged service to achieve remote code execution (GitHub Advisory, GHES 3.19 Release Notes).
Successful exploitation results in full compromise of the GHES appliance — an attacker can extract sensitive instance secrets via timing analysis and subsequently use those secrets to execute arbitrary code remotely, achieving high confidentiality, integrity, and availability impact. When private mode is disabled, exploitation is entirely unauthenticated; when private mode is enabled, any authenticated user can exploit the flaw. The ability to execute code on the appliance could enable lateral movement to connected systems, exfiltration of source code and credentials, and persistent access to the enterprise development environment (GitHub Advisory, GHES 3.20 Release Notes).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability was reported through the GitHub Bug Bounty program. The EPSS score is approximately 0.89%, indicating a relatively low (but non-negligible) probability of exploitation in the near term. NVD SSVC assessment notes the vulnerability is automatable with total technical impact. It is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
https://<ghes-host>/notebook-viewer?url=http://127.0.0.1:<internal_port>/...). The scheme and host validation passes, but the port is not rejected.?url=http://127.0.0.1:<port>/); anomalous timing patterns in notebook viewer request logs suggesting automated enumeration.GitHub has released patched versions addressing CVE-2026-77987 across all affected branches: 3.17.21, 3.18.15, 3.19.12, 3.20.8, 3.21.6, and 3.22.1. The fix causes GHES to reject notebook viewer URLs that specify an explicit port. Administrators should upgrade to the appropriate patched version immediately. As an interim workaround if patching is not immediately possible, restrict network access to the GHES instance to trusted networks only, and enable private mode to require authentication for all access, reducing the unauthenticated attack surface (GHES 3.17 Release Notes, GHES 3.22 Release Notes).
The vulnerability received coverage from security news outlets including SecurityOnline and UnderCodeNews, which highlighted the critical nature of the SSRF-to-RCE chain (SecurityOnline, UnderCodeNews). The Centre for Cybersecurity Belgium (CCB) issued a warning advisory about the vulnerability (CCB Advisory). Community discussion was noted on Infosec.exchange, reflecting awareness among security practitioners of the severity of the timing-oracle-based secret extraction technique.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."