CVE 6.3 MEDIUM

Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via unauthenticated API endpoint_CVE-2026-7541

6.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U

Description

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by sending crafted requests with deeply nested JSON payloads to an unauthenticated API endpoint. The endpoint parsed user-controlled JSON request bodies without size or depth limits, causing excessive CPU and memory consumption. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.2, 3.19.6, 3.18.9, 3.17.15, and 3.16.18. This vulnerability was reported via the GitHub Bug Bounty program.

Basic Information

ID CVE-2026-7541
Source GitHub_P
Published May 7, 2026 at 21:18

Affected Product

Vendor GitHub
Product Enterprise Server
Version 3.16.0
Affected Versions GitHub Enterprise Server 3.16.0
GitHub Enterprise Server 3.17.0
GitHub Enterprise Server 3.18.0
GitHub Enterprise Server 3.19.0
GitHub Enterprise Server 3.20.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.