Threat reportVulnerabilityTL-2026-0605

GitHub Enterprise Server 3.20.3 — Pre-Auth SSRF in Upload Endpoint (CVE-2026-9312) + Bundled "Dirty Frag" Kernel LPEs (CVE-2026-43284, CVE-2026-43500) + Mandatory GPG Signing Key Rotation

criticalMONITORING

GitHub Enterprise Server 3.20.3 (TL-2026-0605), also tracked as GHES 3.20.3 Patch Release, is a critical-severity software vulnerability scored CVSS 9.6, first published 2026-05-27. It has no confirmed attribution, affects GitHub GitHub Enterprise Server, references 5 CVEs (CVE-2026-9312, CVE-2026-43284, CVE-2026-43500), maps to 24 MITRE ATT&CK techniques (T1046, T1059, T1068), and is covered by 9 detection rules and 18 indicators of compromise.

CVSS
9.6/10Critical
CVEs
5Referenced vulnerabilities
Techniques
24MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
18Indicators of compromise

Key facts for TL-2026-0605

Threat ID
TL-2026-0605
Also known as
GHES 3.20.3 Patch Release, Dirty Frag (GHES bundle)
Severity
CRITICAL
CVSS
9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L)
Status
MONITORING
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, financial, government, defense, healthcare, manufacturing, telecommunications, education, energy
Target regions
Global, North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
18

How GitHub Enterprise Server 3.20.3 works

GitHub Enterprise Server (GHES) 3.20.3 closes a critical pre-authentication server-side request forgery vulnerability in an upload endpoint (CVE-2026-9312) that let a network-adjacent attacker coerce internal HTTP calls from the appliance, potentially reaching internal services and exposing credentials or configuration. The release also bundles fixes for two high-severity Linux kernel local privilege-escalation flaws in the IPsec ESP and RxRPC networking subsystems — branded "Dirty Frag" (CVE-2026-43284, CVE-2026-43500) — and additional SSRF/secret-exposure hardening (CVE-2026-5921, CVE-2026-8606). GitHub has rotated the GPG signing key for GHES release packages; administrators must run the official key-rotation procedure before upgrading or signature verification will fail and the upgrade will be blocked.

GitHub Enterprise Server 3.20.3, released on 2026-05-27, is a security-driven patch release that closes one critical and multiple high-severity vulnerabilities in the self-hosted GHES appliance and rotates the GPG key used to sign GHES release packages.

## CVE-2026-9312 — Pre-Auth SSRF in Upload Endpoint (Critical)

The headline fix is a critical pre-authentication server-side request forgery in a GHES upload endpoint. Input parameters accepted by the endpoint were not strictly validated, allowing a network-adjacent attacker — with no authentication required — to craft upload requests that caused the GHES server to issue internal HTTP calls to attacker-controlled destinations and internal addresses. Because the request originates from the GHES appliance itself, the attacker can reach internal services on the same network segment, the appliance's own loopback management interfaces, and cloud metadata endpoints (e.g. 169.254.169.254 on AWS/Azure/GCP-hosted instances), potentially exfiltrating instance credentials, IAM role tokens, environment configuration, and other secrets accessible to the appliance.

The vulnerability is a general-purpose SSRF primitive: response data and timing differences can be observed to enumerate internal services and to perform blind SSRF against authenticated internal APIs. Reported via the GitHub Bug Bounty program. GitHub mitigated by tightening input validation, applying destination allow-listing to the endpoint, and preventing the upload path from emitting arbitrary outbound HTTP requests.

## CVE-2026-43284 & CVE-2026-43500 — "Dirty Frag" Kernel LPEs (High)

GHES 3.20.3 also ships an updated bundled Linux kernel that fixes two high-severity local privilege-escalation flaws collectively branded "Dirty Frag" — one in the IPsec ESP (XFRM) subsystem (CVE-2026-43284) and one in the RxRPC networking subsystem (CVE-2026-43500). The Dirty Frag family of bugs abuses fragmentation/coalescing logic in the kernel networking path to drive an out-of-bounds page-cache write, allowing a local unprivileged user with shell access on the appliance to corrupt kernel memory and gain root.

In the GHES context this is most dangerous on multi-tenant or large-team appliances where multiple internal users, CI runners, or automated processes have shell access (admin shell, support-bundle generation contexts, scripted maintenance). A low-privileged foothold (e.g. an attacker who chained the SSRF, leveraged a separate webshell, or compromised a legitimate operator account) can be reliably escalated to root, granting full control over the underlying OS, the entire Git data set, all repository secrets, and all customer source code stored on the appliance.

## CVE-2026-5921 & CVE-2026-8606 — Additional Hardening

GHES 3.20.3 also rolls in fixes carried over from earlier 3.20.x updates: a timing side-channel in the notebook viewer that could leak environment variables to an attacker (CVE-2026-5921), and an internal packages endpoint that could be abused for unauthenticated SSRF when private mode is disabled (CVE-2026-8606). Both were reported through the GitHub Bug Bounty program.

## GPG Signing Key Rotation (Operational Hard Gate)

As part of this release, GitHub has revoked the previous GPG signing key for GHES release packages and signed 3.20.3 (and all subsequent images) with a new key. Administrators must run GitHub's official key-rotation script/procedure to install the new trusted public key on every appliance before attempting the 3.20.3 upgrade. Skipping the rotation step will cause the appliance's signature verification to fail and the upgrade to be blocked — delaying deployment of the SSRF and kernel LPE fixes.

## Operational Impact and Recommended Posture

Any GHES appliance reachable from a less-trusted network is at risk of pre-auth SSRF exploitation; if shell access is shared by multiple teams, the chained SSRF -> credential theft -> remote authenticated foothold -> kernel LPE -> root path is realistic. GitHub recommends that all GHES 3.20.x customers prioritize this upgrade after completing the GPG key rotation, and revisit network segmentation on upload, notebook, and packages endpoints. There is no public PoC at time of disclosure and no confirmed in-the-wild exploitation; severity is driven by the network reachability, lack of authentication, and proven escalation path on the same appliance.

MITRE ATT&CK techniques used in TL-2026-0605

Discovery

T1046 Network Service Discovery; T1526 Cloud Service Discovery; T1580 Cloud Infrastructure Discovery

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

Defense Evasion

T1070 Indicator Removal

Command and Control

T1071 Application Layer Protocol

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Persistence

T1098 Account Manipulation; T1543 Create or Modify System Process

Collection

T1213 Data from Information Repositories; T1602 Data from Configuration Repository

Credential Access

T1528 Steal Application Access Token; T1552 Unsecured Credentials

Lateral Movement

T1550 Use Alternate Authentication Material

defense-impairment

T1553 Subvert Trust Controls

Impact

T1565 Data Manipulation

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1587 Develop Capabilities

Reconnaissance

T1590 Gather Victim Network Information; T1595 Active Scanning

Affected products and versions in GitHub Enterprise Server 3.20.3

  • GitHub — GitHub Enterprise Server
    Vulnerable versions: 3.20.0; 3.20.1; 3.20.2
    Fixed in: 3.20.3
  • Linux Kernel — Linux kernel (bundled with GHES appliance image)
    Vulnerable versions: Versions bundled with GHES 3.20.0 — 3.20.2 (XFRM/ESP and RxRPC subsystems)
    Fixed in: Kernel bundled with GHES 3.20.3 appliance image

Remediation for GitHub Enterprise Server 3.20.3

Patches

  • Upgrade GitHub Enterprise Server to 3.20.3 (after completing the GPG signing key rotation).
  • The 3.20.3 image bundles the patched Linux kernel that fixes CVE-2026-43284 (xfrm/ESP) and CVE-2026-43500 (RxRPC) — no manual kernel patching is required if you upgrade the appliance image.

Immediate actions

  • Inventory all GitHub Enterprise Server appliances and identify any on 3.20.x prior to 3.20.3.
  • Run GitHub's official GPG signing key rotation procedure on every appliance BEFORE attempting upgrade — skipping this step will block the 3.20.3 install.
  • Restrict network access to GHES upload, notebook, and internal packages endpoints to trusted source networks only (firewall ACLs or reverse-proxy allow-list).
  • Audit and restrict shell access on the GHES appliance — the bundled Dirty Frag kernel LPEs (CVE-2026-43284, CVE-2026-43500) require a local foothold to weaponize.
  • Block outbound HTTP/HTTPS from the GHES appliance to cloud metadata IPs (169.254.169.254, fd00:ec2::254) and to internal management subnets at the network layer until patched.

Workarounds

  • If 3.20.3 cannot be deployed immediately, place the GHES upload endpoint behind a reverse proxy that strips/normalizes upload parameters and blocks requests with URL-shaped values in destination-controlling fields.
  • Disable the notebook viewer feature if not in active use (mitigates CVE-2026-5921 environment-variable leak side-channel).
  • Ensure private mode is ENABLED on internet-facing GHES instances to neutralize the internal packages endpoint SSRF (CVE-2026-8606).
  • Remove or rotate any cloud IAM role attached to the GHES appliance to the minimum permissions necessary, reducing blast radius if SSRF-to-metadata succeeds.

Longer-term hardening

  • Enforce destination allow-listing at the network egress layer for GHES — egress to only the explicitly required external services (e.g. github.com mirror endpoints, license verification).
  • Adopt IMDSv2 on AWS-hosted GHES instances and equivalent metadata service hardening on Azure/GCP to defeat SSRF-to-metadata pivot.
  • Implement segmentation so the GHES appliance cannot reach internal admin planes (Vault, secrets managers, CI/CD orchestrators) directly.
  • Standardize a quarterly GHES patching cadence with a documented signing-key-rotation runbook so future key rotations do not delay critical security patches.
  • Deploy EDR/auditd on the GHES underlying OS to detect kernel LPE primitives — XFRM/ESP fragmentation anomalies, RxRPC socket use by non-root processes.

CVEs associated with GitHub Enterprise Server 3.20.3

CVE-2026-9312, CVE-2026-43284, CVE-2026-43500, CVE-2026-5921, CVE-2026-8606

Weaknesses (CWE) in GitHub Enterprise Server 3.20.3

CWE-918, CWE-20, CWE-787, CWE-119, CWE-203, CWE-200, CWE-269

Timeline of GitHub Enterprise Server 3.20.3

  • External researchers submit reports of multiple SSRF and secret-exposure issues in GitHub Enterprise Server 3.20.x via the GitHub Bug Bounty program, including the upload-endpoint SSRF later assigned CVE-2026-9312.
  • GitHub engineering identifies that the bundled GHES Linux kernel is affected by two high-severity local privilege-escalation flaws in the IPsec ESP (XFRM) and RxRPC subsystems, later branded "Dirty Frag." GitHub requests CVE-2026-43284 and CVE-2026-43500.
  • GitHub decides to rotate the GPG signing key used to sign GHES release packages as part of the 3.20.3 release; engineering develops the official key-rotation script and admin procedure.
  • CVE-2026-5921 (notebook viewer timing side-channel — environment-variable leak) and CVE-2026-8606 (internal packages endpoint unauthenticated SSRF when private mode is disabled) assigned for issues found via the bug bounty program.
  • GHES 3.20.3 image finalized with patched kernel, tightened upload-endpoint validation, destination allow-listing, and re-signed with the new GPG signing key.
  • No confirmed in-the-wild exploitation at time of disclosure; no public proof-of-concept yet. Risk assessment driven by network reachability, lack of authentication, and chained SSRF -> credential theft -> kernel LPE path.
  • Threadlinqs Intelligence assigns TL-2026-0605 and begins research, detection, and simulation pipeline.
  • GitHub Bug Bounty disclosures and NVD entries published; administrators advised to run GPG key rotation BEFORE upgrade to avoid signature-verification failure.
  • GitHub publishes GHES 3.20.3 with security advisories for CVE-2026-9312, CVE-2026-43284, CVE-2026-43500, CVE-2026-5921, and CVE-2026-8606. Cyber Security News publishes coverage and signing-key-rotation guidance.
  • As of 2026-05-29, GitHub fixed all five CVEs in GHES 3.20.3 (NVD lists branch fixes 3.20.4/3.21.1) and none are in CISA KEV with no confirmed in-the-wild exploitation. It stays a live concern: public Dirty Frag (CVE-2026-43284/43500) exploit code now circulates after a May 7 embargo break, so unpatched 3.20.x appliances remain at risk.

Sources cited for GitHub Enterprise Server 3.20.3

Detection coverage for TL-2026-0605

As of 2026-05-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0605 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
18 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats