GitHub security advisory (AV26-720)
Serial number: AV26-720 Date: July 20, 2026 On July 16, 2026, GitHub published security advisories to address vulnerabilities in the following products: GitHub Enterprise Server – versions 3.21.x prior to 3.21.3 GitHub Enterprise Server – versions 3.20.x prior to 3.20.5 GitHub Enterprise Server – versions 3.19.x prior to 3.19.9 GitHub Enterprise Server – versions 3.18.x prior to 3.18.12 GitHub Enterprise Server – versions 3.17.x prior to 3.17.18 The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. Enterprise Server 3.21.3 Enterprise Server 3.20.5 Enterprise Server 3.19.9 Enterprise Server 3.18.12 Enterprise Server 3.17.18
CSIRTS triage
- What
- Multiple vulnerabilities have been identified in GitHub Enterprise Server.
- Who is affected
- Users and administrators of affected versions of GitHub Enterprise Server.
- Urgency
- Urgency is unclear due to unknown severity.
- Action
- Upgrade to the latest versions of GitHub Enterprise Server.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch GitHub Enterprise Server
Get an email when a new GitHub Enterprise Server advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/github-security-advisory-av26-720
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30