GitHub security advisory (AV26-783)
Serial number: AV26-783 Date: August 6, 2026 As of August 5, 2026, GitHub is affected by vulnerabilities in the following product: Enterprise Server 3.17.0 Prior to 3.17.16 3.17.0 Prior to 3.17.19 3.18.0 Prior to 3.18.10 3.18.0 Prior to 3.18.13 3.19.0 Prior to 3.19.10 3.19.0 Prior to 3.19.7 3.20.0 Prior to 3.20.3 3.20.0 Prior to 3.20.6 3.21.0 Prior to 3.21.4 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Release notes - GitHub Enterprise Server 3.17 Docs Release notes - GitHub Enterprise Server 3.18 Docs Release notes - GitHub Enterprise Server 3.19 Docs Release notes - GitHub Enterprise Server 3.20 Docs Release notes - GitHub Enterprise Server 3.21 Docs GitHub Enterprise Server releases - GitHub Enterprise Server 3.19 Docs
CSIRTS triage
- What
- GitHub Enterprise Server contains unspecified vulnerabilities across multiple versions.
- Who is affected
- GitHub Enterprise Server deployments running versions 3.17 through 3.21 prior to their respective patch releases.
- Urgency
- Unknown; vulnerability classes and severity not disclosed in advisory.
- Action
- Apply GitHub Enterprise Server security patches to the specified minimum versions for each release branch.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Enterprise Server
Get an email when a new Enterprise Server advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/github-security-advisory-av26-783
More from Canadian Centre for Cyber Security
- unknownDjango security advisory (AV26-786)2026-08-06
- unknownCisco security advisory (AV26-785)2026-08-06
- unknownFoxit security advisory (AV26-784)2026-08-06
- unknownJenkins security advisory (AV26-782)2026-08-06
- criticalProgress security advisory (AV26-781)2026-08-06