Pre-authentication SSRF in GitHub Enterprise Server upload endpoint
CVE-2026-9312 is a server-side request forgery vulnerability in GitHub Enterprise Server (GHES) affecting versions prior to 3.22. The flaw exists in an upload endpoint where insufficient input validation allows an unauthenticated attacker to submit crafted request parameters containing path traversal content. By abusing this validation gap, the attacker can bypass the intended request flow and cause the server to issue internal API or HTTP requests to unintended internal destinations. The issue is described as pre-authentication and network-reachable, meaning exploitation does not require a valid account if the vulnerable endpoint is exposed. The vulnerable behavior can redirect internal calls and enable access to internal services that are not normally reachable by external users, with potential exposure of sensitive credentials or related internal data.
Are you exposed to this one?
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
Impact, mitigation & remediation
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
Impact
What an attacker gets, and what they’ve been doing with it.
Mitigation
If you can’t patch tonight, do this now.
Remediation
Patch, then assume compromise.
Exploits
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Affected products & vendors
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
Recent activity
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical pre-authentication SSRF vulnerability in a GitHub Enterprise Server upload endpoint that could let a network-access attacker trigger internal HTTP requests and potentially expose credentials or configuration data.
A pre-authentication SSRF vulnerability in a GitHub Enterprise Server upload endpoint caused by insufficient input validation, allowing crafted requests to internal services and possible exposure of sensitive credentials.
The version that knows your environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.