Skip to finding
important · Edge devices

GitHub Enterprise Server's notebook viewer can lead a network caller from blind SSRF to appliance code execution.

Affects

GitHub Enterprise Server, self-hosted source-code collaboration appliances; unauthenticated exposure applies when private mode is disabled.

Unsafe handling of an explicit URL port permits blind SSRF to co-located services. A timing oracle can recover appliance secrets, which are then used in a separate internal interaction to execute code.

Detail and 5 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 24, 2026