CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GitHub security advisory (AV26-720)

unknown
Serial number: AV26-720 Date: July 20, 2026 On July 16, 2026, GitHub published security advisories to address vulnerabilities in the following products: GitHub Enterprise Server – versions 3.21.x prior to 3.21.3 GitHub Enterprise Server – versions 3.20.x prior to 3.20.5 GitHub Enterprise Server – versions 3.19.x prior to 3.19.9 GitHub Enterprise Server – versions 3.18.x prior to 3.18.12 GitHub Enterprise Server – versions 3.17.x prior to 3.17.18 The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. Enterprise Server 3.21.3 Enterprise Server 3.20.5 Enterprise Server 3.19.9 Enterprise Server 3.18.12 Enterprise Server 3.17.18

CSIRTS triage

vendor: GitHubproduct: GitHub Enterprise ServerOtheraffected: 3.21.x prior to 3.21.3, 3.20.x prior to 3.20.5, 3.19.x prior to 3.19.9, 3.18.x prior to 3.18.12, 3.17.x prior to 3.17.18
What
Multiple vulnerabilities have been identified in GitHub Enterprise Server.
Who is affected
Users and administrators of affected versions of GitHub Enterprise Server.
Urgency
Urgency is unclear due to unknown severity.
Action
Upgrade to the latest versions of GitHub Enterprise Server.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch GitHub Enterprise Server

Get an email when a new GitHub Enterprise Server advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-07-20
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/github-security-advisory-av26-720

More from Canadian Centre for Cyber Security