Description
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumption and exhaust the pool of request-handling worker processes by sending a crafted form-encoded HTTP POST request containing deeply nested parameters. Because request parameters were parsed before routing and authentication, any POST endpoint could be used to trigger the condition, which could render the instance unresponsive. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.3, 3.19.7, 3.18.10, and 3.17.16.
Published: 2026-08-05
Score: 6.6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A denial of service vulnerability exists in GitHub Enterprise Server that allows an unauthenticated attacker to exhaust the pool of request‑handling worker processes and consume excessive CPU by sending a crafted form‑encoded HTTP POST request with deeply nested parameters. Because request parameters are parsed before routing and authentication, any POST endpoint can trigger the condition, rendering the instance unresponsive. The associated weakness is CWE‑674.

Affected Systems

Vendors affected are GitHub Enterprise Server. All versions preceding 3.21 are vulnerable. The issue is fixed in releases 3.20.3, 3.19.7, 3.18.10, and 3.17.16.

Risk and Exploitability

The CVSS score of 6.6 indicates a moderate impact, and the EPSS score is not available, so the likelihood of exploitation is uncertain but not considered high. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the denial of service by sending any unauthenticated POST request with deep nesting, so the vector is inferred to be HTTP over the network. Since the flaw is generic to all POST endpoints, the risk extends broadly to any externally reachable instance of GitHub Enterprise Server that has not applied the patch.

Generated by OpenCVE AI on August 5, 2026 at 21:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched release such as GitHub Enterprise Server 3.20.3 or later to remove the vulnerability.
  • If an immediate upgrade is not possible, restrict external traffic to POST endpoints or limit request size through a front‑end firewall or reverse proxy to reduce the impact of deep nesting.
  • Monitor CPU usage and worker process counts for abnormal spikes, and apply rate limiting or temporary service restarts to mitigate ongoing denial of service attempts.

Generated by OpenCVE AI on August 5, 2026 at 21:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Github
Github enterprise Server
Vendors & Products Github
Github enterprise Server

Wed, 05 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumption and exhaust the pool of request-handling worker processes by sending a crafted form-encoded HTTP POST request containing deeply nested parameters. Because request parameters were parsed before routing and authentication, any POST endpoint could be used to trigger the condition, which could render the instance unresponsive. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.3, 3.19.7, 3.18.10, and 3.17.16.
Title Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters
Weaknesses CWE-674
References
Metrics cvssV4_0

{'score': 6.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U'}


Subscriptions

Github Enterprise Server
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_P

Published:

Updated: 2026-08-05T20:12:57.955Z

Reserved: 2026-07-16T21:29:33.097Z

Link: CVE-2026-15996

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T21:30:16Z

Weaknesses