Skip to content

Commit 2458331

Browse files
Added CVE and bounty program link in the release notes (#61424)
Co-authored-by: Isaac Brown <101839405+isaacmbrown@users.noreply.github.com>
1 parent 936dbe9 commit 2458331

5 files changed

Lines changed: 5 additions & 5 deletions

File tree

data/release-notes/enterprise-server/3-16/19.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ sections:
88
- |
99
**HIGH**: An attacker with local access to the instance could escalate privileges to root by exploiting the Dirty Frag Linux kernel vulnerabilities in the IPsec ESP and RxRPC networking subsystems. GitHub has requested [CVE-2026-43284](https://ubuntu.com/security/CVE-2026-43284) and [CVE-2026-43500](https://ubuntu.com/security/CVE-2026-43500) for these vulnerabilities.
1010
- |
11-
**HIGH**: An attacker could extract sensitive environment variables from a GitHub Enterprise Server instance through a timing side-channel attack against the security advisories package lookup feature. On instances with GitHub Packages enabled, the package URL endpoint did not validate the supplied package name, enabling a Server-Side Request Forgery (SSRF) to internal services. This required no authentication when private mode was disabled, or any authenticated user otherwise. To mitigate this issue, GitHub removed the affected endpoint from GitHub Enterprise Server. GitHub has requested CVE ID CVE-2026-8606 for this vulnerability, which was reported via the GitHub Bug Bounty program.
11+
**HIGH**: An attacker could extract sensitive environment variables from a GitHub Enterprise Server instance through a timing side-channel attack against the security advisories package lookup feature. On instances with GitHub Packages enabled, the package URL endpoint did not validate the supplied package name, enabling a Server-Side Request Forgery (SSRF) to internal services. This required no authentication when private mode was disabled, or any authenticated user otherwise. To mitigate this issue, GitHub removed the affected endpoint from GitHub Enterprise Server. GitHub has requested CVE ID [CVE-2026-8606](https://www.cve.org/cverecord?id=CVE-2026-8606) for this vulnerability, which was reported via the [GitHub Bug Bounty program](https://bounty.github.com/).
1212
- |
1313
Packages have been updated to the latest security versions.
1414
bugs:

data/release-notes/enterprise-server/3-17/16.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ sections:
88
- |
99
**HIGH**: An attacker with local access to the instance could escalate privileges to root by exploiting the Dirty Frag Linux kernel vulnerabilities in the IPsec ESP and RxRPC networking subsystems. GitHub has requested [CVE-2026-43284](https://ubuntu.com/security/CVE-2026-43284) and [CVE-2026-43500](https://ubuntu.com/security/CVE-2026-43500) for these vulnerabilities.
1010
- |
11-
**HIGH**: An attacker could extract sensitive environment variables from a GitHub Enterprise Server instance through a timing side-channel attack against the security advisories package lookup feature. On instances with GitHub Packages enabled, the package URL endpoint did not validate the supplied package name, enabling a Server-Side Request Forgery (SSRF) to internal services. This required no authentication when private mode was disabled, or any authenticated user otherwise. To mitigate this issue, GitHub removed the affected endpoint from GitHub Enterprise Server. GitHub has requested CVE ID CVE-2026-8606 for this vulnerability, which was reported via the GitHub Bug Bounty program.
11+
**HIGH**: An attacker could extract sensitive environment variables from a GitHub Enterprise Server instance through a timing side-channel attack against the security advisories package lookup feature. On instances with GitHub Packages enabled, the package URL endpoint did not validate the supplied package name, enabling a Server-Side Request Forgery (SSRF) to internal services. This required no authentication when private mode was disabled, or any authenticated user otherwise. To mitigate this issue, GitHub removed the affected endpoint from GitHub Enterprise Server. GitHub has requested CVE ID [CVE-2026-8606](https://www.cve.org/cverecord?id=CVE-2026-8606) for this vulnerability, which was reported via the [GitHub Bug Bounty program](https://bounty.github.com/).
1212
- |
1313
Packages have been updated to the latest security versions.
1414
bugs:

data/release-notes/enterprise-server/3-18/10.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ sections:
88
- |
99
**HIGH**: An attacker with local access to the instance could escalate privileges to root by exploiting the Dirty Frag Linux kernel vulnerabilities in the IPsec ESP and RxRPC networking subsystems. GitHub has requested [CVE-2026-43284](https://ubuntu.com/security/CVE-2026-43284) and [CVE-2026-43500](https://ubuntu.com/security/CVE-2026-43500) for these vulnerabilities.
1010
- |
11-
**HIGH**: An attacker could extract sensitive environment variables from a GitHub Enterprise Server instance through a timing side-channel attack against the security advisories package lookup feature. On instances with GitHub Packages enabled, the package URL endpoint did not validate the supplied package name, enabling a Server-Side Request Forgery (SSRF) to internal services. This required no authentication when private mode was disabled, or any authenticated user otherwise. To mitigate this issue, GitHub removed the affected endpoint from GitHub Enterprise Server. GitHub has requested CVE ID CVE-2026-8606 for this vulnerability, which was reported via the GitHub Bug Bounty program.
11+
**HIGH**: An attacker could extract sensitive environment variables from a GitHub Enterprise Server instance through a timing side-channel attack against the security advisories package lookup feature. On instances with GitHub Packages enabled, the package URL endpoint did not validate the supplied package name, enabling a Server-Side Request Forgery (SSRF) to internal services. This required no authentication when private mode was disabled, or any authenticated user otherwise. To mitigate this issue, GitHub removed the affected endpoint from GitHub Enterprise Server. GitHub has requested CVE ID [CVE-2026-8606](https://www.cve.org/cverecord?id=CVE-2026-8606) for this vulnerability, which was reported via the [GitHub Bug Bounty program](https://bounty.github.com/).
1212
- |
1313
Packages have been updated to the latest security versions.
1414
bugs:

data/release-notes/enterprise-server/3-19/7.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ sections:
88
- |
99
**HIGH**: An attacker with local access to the instance could escalate privileges to root by exploiting the Dirty Frag Linux kernel vulnerabilities in the IPsec ESP and RxRPC networking subsystems. GitHub has requested [CVE-2026-43284](https://ubuntu.com/security/CVE-2026-43284) and [CVE-2026-43500](https://ubuntu.com/security/CVE-2026-43500) for these vulnerabilities.
1010
- |
11-
**HIGH**: An attacker could extract sensitive environment variables from a GitHub Enterprise Server instance through a timing side-channel attack against the security advisories package lookup feature. On instances with GitHub Packages enabled, the package URL endpoint did not validate the supplied package name, enabling a Server-Side Request Forgery (SSRF) to internal services. This required no authentication when private mode was disabled, or any authenticated user otherwise. To mitigate this issue, GitHub removed the affected endpoint from GitHub Enterprise Server. GitHub has requested CVE ID CVE-2026-8606 for this vulnerability, which was reported via the GitHub Bug Bounty program.
11+
**HIGH**: An attacker could extract sensitive environment variables from a GitHub Enterprise Server instance through a timing side-channel attack against the security advisories package lookup feature. On instances with GitHub Packages enabled, the package URL endpoint did not validate the supplied package name, enabling a Server-Side Request Forgery (SSRF) to internal services. This required no authentication when private mode was disabled, or any authenticated user otherwise. To mitigate this issue, GitHub removed the affected endpoint from GitHub Enterprise Server. GitHub has requested CVE ID [CVE-2026-8606](https://www.cve.org/cverecord?id=CVE-2026-8606) for this vulnerability, which was reported via the [GitHub Bug Bounty program](https://bounty.github.com/).
1212
- |
1313
Packages have been updated to the latest security versions.
1414
bugs:

data/release-notes/enterprise-server/3-20/3.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ sections:
88
- |
99
**HIGH**: An attacker with local access to the instance could escalate privileges to root by exploiting the Dirty Frag Linux kernel vulnerabilities in the IPsec ESP and RxRPC networking subsystems. GitHub has requested [CVE-2026-43284](https://ubuntu.com/security/CVE-2026-43284) and [CVE-2026-43500](https://ubuntu.com/security/CVE-2026-43500) for these vulnerabilities.
1010
- |
11-
**HIGH**: An attacker could extract sensitive environment variables from a GitHub Enterprise Server instance through a timing side-channel attack against the security advisories package lookup feature. On instances with GitHub Packages enabled, the package URL endpoint did not validate the supplied package name, enabling a Server-Side Request Forgery (SSRF) to internal services. This required no authentication when private mode was disabled, or any authenticated user otherwise. To mitigate this issue, GitHub removed the affected endpoint from GitHub Enterprise Server. GitHub has requested CVE ID CVE-2026-8606 for this vulnerability, which was reported via the GitHub Bug Bounty program.
11+
**HIGH**: An attacker could extract sensitive environment variables from a GitHub Enterprise Server instance through a timing side-channel attack against the security advisories package lookup feature. On instances with GitHub Packages enabled, the package URL endpoint did not validate the supplied package name, enabling a Server-Side Request Forgery (SSRF) to internal services. This required no authentication when private mode was disabled, or any authenticated user otherwise. To mitigate this issue, GitHub removed the affected endpoint from GitHub Enterprise Server. GitHub has requested CVE ID [CVE-2026-8606](https://www.cve.org/cverecord?id=CVE-2026-8606) for this vulnerability, which was reported via the [GitHub Bug Bounty program](https://bounty.github.com/).
1212
- |
1313
Packages have been updated to the latest security versions.
1414
bugs:

0 commit comments

Comments
 (0)