CVE DATABASE / CVE-2026-3854
CVE-2026-3854
Summary
An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. During a git push operation, user-supplied push option values were not properly sanitized before being included in internal service headers. Because the internal header format used a delimiter character that could also appear in user input, an attacker could inject additional metadata fields through crafted push option values. This vulnerability was reported via the GitHub Bug Bounty program and has been fixed in GitHub Enterprise Server versions 3.14.25, 3.15.20, 3.16.16, 3.17.13, 3.18.7 and 3.19.4.
CVSS 3.1 breakdown
| Base score | 8.8 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Attack vector | NETWORK |
| Attack complexity | LOW |
| Privileges required | LOW |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity | HIGH |
| Availability | HIGH |
Weakness type (CWE)
Affected products
Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.
Our coverage
- CVE-2026-31431 Linux Privilege Escalation Detection: Copy Fail Patch Verification Checklist
- CVE-2026-3854: How the GitHub Enterprise Server RCE Works and How to Verify You're Patched
References
- https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.25
- https://docs.github.com/en/enterprise-server@3.15/admin/release-notes#3.15.20
- https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.16
- https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.13
- https://docs.github.com/en/enterprise-server@3.18/admin/release-notes#3.18.7
- https://docs.github.com/en/enterprise-server@3.19/admin/release-notes#3.19.4
- https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
Data: NIST NVD. NVD last modified 2026-04-28. Always verify against the vendor advisory before acting.