External risk intelligence

GitHub Enterprise Server SSRF to RCE via Notebook Viewer.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-77987

GitHub Enterprise Server is commonly deployed as an internet-facing application platform or development gateway. The vulnerability exists within the notebook viewer feature, which is accessible to users interacting with the enterprise instance. Given the product's typical role as a centralized, externally reachable service for development teams, it is frequently exposed to network access.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability in GitHub Enterprise Server's notebook viewer could allow an attacker to execute code on the server. This is achieved by exploiting a flaw that enables the redirection of requests to internal services, with timing information then used to extract secrets that facilitate code execution.

  • A server flaw enables secret extraction and code execution.
  • This impacts how we secure development platforms.
  • Confirm if our GitHub Enterprise Server is affected.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted URL to the notebook viewer, which processes user-supplied links. Although the viewer checks the URL's scheme and host, it overlooks the port number. This allows an attacker to redirect requests to internal services running on the same appliance. While direct response bodies aren't returned, the timing of responses can reveal sensitive instance secrets, enabling an attacker to gain remote code execution.

  • Requires network access to the instance.
  • Triggered by viewing a crafted notebook.
  • Can lead to sensitive data exposure and RCE.

Live Threat

Current exploitation, exposure, and threat context

The notebook viewer in GitHub Enterprise Server could allow an attacker to extract instance secrets by timing server responses. These secrets, when combined with network access to the instance, could enable remote code execution on the appliance. This risk is supported when network access to the instance is available and private mode is disabled or when an authenticated user is present if private mode is enabled.

  • Instance secrets and administrative control.
  • Timing responses to infer secrets.
  • Remote code execution on the appliance.

Operational Fix

Recommended remediation, mitigation, and detection steps

GitHub Enterprise Server administrators and the platform team are likely responsible for managing this vulnerability. The first practical step is to inventory all GitHub Enterprise Server instances, confirm their network exposure and business criticality, and identify the accountable owner for each instance before planning remediation.

  • Platform and administrators own the issue.
  • Verify instance reachability and criticality first.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is GitHub Enterprise Server?

It is a self-hosted platform used by organizations to manage code, collaborate on development projects, and host repositories on their own infrastructure. The specific notebook viewer component allows users to render and interact with data-rich files directly within the platform. By providing a centralized workspace, it acts as a critical gateway for development teams, frequently handling proprietary code and organizational secrets.

What is the vulnerability in CVE-2026-77987?

This flaw is a Server-Side Request Forgery (SSRF) combined with a timing side-channel attack (CWE-918 and CWE-208). While the software checked the destination host, it failed to validate the port. An attacker can use this oversight to probe internal services on the same appliance. By measuring the time the server takes to respond, they can slowly guess sensitive secrets, which may ultimately be used to gain unauthorized control over the server.

How is this vulnerability triggered?

An attacker triggers it by submitting a specially crafted URL to the notebook viewer. The issue does not depend on the server returning the actual content of the internal request; instead, the time the server takes to process the request acts as a data oracle. Access to the instance is required, but the bug is not triggered if the notebook viewer is not used or if the input URL does not target an internal port.

Do I need to worry if my instance is internal?

Yes, but the risk profile varies. Halo Surface Signal notes that GitHub Enterprise Server is often deployed as an internet-facing gateway, making it a primary target for external actors. However, if your instance is strictly internal, the attacker must first gain network access to your private environment. If private mode is enabled, the attacker must also have a valid user account to interact with the notebook viewer.

What should I do to address this issue?

Start by identifying all GitHub Enterprise Server instances in your environment and checking their current version numbers. If you are running a version between 3.17 and 3.22, you are affected. Once you have an inventory of the impacted appliances, prioritize patching them to the specified secure versions (3.22.1, 3.21.6, 3.20.8, 3.19.12, 3.18.15, or 3.17.21) as the primary way to remediate the flaw.

References