CVE-2026-19118
Last modified
CVE-2026-19118 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access to a repository and precise timing of concurrent upload requests. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access to a repository and precise timing of concurrent upload requests. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5. This vulnerability was reported via the GitHub Bug Bounty program.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Github | Enterprise Server | < 3.17.20 |
| Github | Enterprise Server | >= 3.18.0, < 3.18.14 |
| Github | Enterprise Server | >= 3.19.0, < 3.19.11 |
| Github | Enterprise Server | >= 3.20.0, < 3.20.7 |
| Github | Enterprise Server | >= 3.21.0, < 3.21.5 |
References
- https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.20Release Notes, Vendor Advisory
- https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.14Release Notes, Vendor Advisory
- https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.11Release Notes, Vendor Advisory
- https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.7Release Notes, Vendor Advisory
- https://docs.github.com/en/enterprise-server@3.21/admin/release-notes#3.21.5Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-19118?
How severe is CVE-2026-19118?
How do I fix CVE-2026-19118?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1911The Twitter Feeds plugin for WordPress is vulnerable to Stor…6.4
- CVE-2026-19110A vulnerability was determined in DataGear up to 5.0.0. The …2.4
- CVE-2026-19111Insecure direct object reference in the mongodb_memory, elas…8.6
- CVE-2026-19113Consul Community Edition and Consul Enterprise 1.3.0 through…5.3
- CVE-2026-19116The User Frontend WordPress plugin before 4.3.11 does not p…8.8
- CVE-2026-19117Under specific conditions, an attacker can register an attac…9.8
- CVE-2026-1912The Citations tools plugin for WordPress is vulnerable to St…6.4
- CVE-2026-19127An issue in the billing and license activation subsystem all…6.5
- CVE-2026-1913The Gallagher Website Design plugin for WordPress is vulnera…6.4
- CVE-2026-19130A flaw was found in the provider-credential-controller compo…5.8
- CVE-2026-19135A JEXL expression sandbox bypass exists in multiple versions…5.4
- CVE-2026-19136A potential command injection vulnerability was reported in …7.8
Are you affected by CVE-2026-19118?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
