CVE-2026-8034
Last modified
CVE-2026-8034 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting URL parser confusion between the validation layer and the HTTP request library. The hostname validation used a different URL parser than the request library, enabling a crafted URL to pass validation while directing the request to an unintended host. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting URL parser confusion between the validation layer and the HTTP request library. The hostname validation used a different URL parser than the request library, enabling a crafted URL to pass validation while directing the request to an unintended host. Exploitation required network access to the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.16.18, 3.17.15, 3.18.9, 3.19.6, and 3.20.2. This vulnerability was reported via the GitHub Bug Bounty program.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Github | Enterprise Server | < 3.16.18 |
| Github | Enterprise Server | >= 3.17.0, < 3.17.15 |
| Github | Enterprise Server | >= 3.18.0, < 3.18.9 |
| Github | Enterprise Server | >= 3.19.0, < 3.19.6 |
| Github | Enterprise Server | >= 3.20.0, < 3.20.2 |
References
- https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.18Release Notes, Vendor Advisory
- https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.15Release Notes, Vendor Advisory
- https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.9Release Notes, Vendor Advisory
- https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.6Release Notes, Vendor Advisory
- https://docs.github.com/en/enterprise-server@3.20/admin/release-notes#3.20.2Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-8034?
How severe is CVE-2026-8034?
How do I fix CVE-2026-8034?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8027A weakness has been identified in FlowiseAI Flowise up to 3.…5.3
- CVE-2026-8028A vulnerability was detected in FlowiseAI Flowise up to 3.0.…3.7
- CVE-2026-8029The ZTE Smart Life app contains an SQL injection vulnerabili…3.9
- CVE-2026-8031A vulnerability was detected in PicoTronica e-Clinic Healthc…5.5
- CVE-2026-8032A flaw has been found in PicoTronica e-Clinic Healthcare Sys…7.3
- CVE-2026-8033A vulnerability has been found in PicoTronica e-Clinic Healt…5.5
- CVE-2026-8035Improper input validation in the NI-PAL kernel driver may al…5.5
- CVE-2026-8036Improper input validation in NI-PAL may allow a local authen…7.8
- CVE-2026-8037OS Command Injection Remote Code Execution Vulnerability in …9.8
- CVE-2026-8038The Faces of Users plugin for WordPress is vulnerable to Sto…6.4
- CVE-2026-8039The Fancy Testimonials plugin for WordPress is vulnerable to…6.4
- CVE-2026-8040The faq shortocde plugin for WordPress is vulnerable to Stor…6.4
Are you affected by CVE-2026-8034?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
