# GitHub Enterprise Server 3.20.3 — Pre-Auth SSRF in Upload Endpoint (CVE-2026-9312) + Bundled "Dirty Frag" Kernel LPEs (CVE-2026-43284, CVE-2026-43500) + Mandatory GPG Signing Key Rotation

> GitHub Enterprise Server (GHES) 3.20.3 closes a critical pre-authentication server-side request forgery vulnerability in an upload endpoint (CVE-2026-9312) that let a network-adjacent attacker coerce internal HTTP calls from the appliance, potentially reaching internal services and exposing credentials or configuration. The release also bundles fixes for two high-severity Linux kernel local privilege-escalation flaws in the IPsec ESP and RxRPC networking subsystems — branded "Dirty Frag" (CVE-2026-43284, CVE-2026-43500) — and additional SSRF/secret-exposure hardening (CVE-2026-5921, CVE-2026-8606). GitHub has rotated the GPG signing key for GHES release packages; administrators must run the official key-rotation procedure before upgrading or signature verification will fail and the upgrade will be blocked.

- **Published:** 2026-05-27T00:00:00Z
- **Last reviewed:** 2026-05-27T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0605
- **ID:** TL-2026-0605
- **Severity:** CRITICAL (CVSS 9.6)
- **Category:** VULNERABILITY
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-9312, CVE-2026-43284, CVE-2026-43500, CVE-2026-5921, CVE-2026-8606

## Description

GitHub Enterprise Server 3.20.3, released on 2026-05-27, is a security-driven patch release that closes one critical and multiple high-severity vulnerabilities in the self-hosted GHES appliance and rotates the GPG key used to sign GHES release packages.

## CVE-2026-9312 — Pre-Auth SSRF in Upload Endpoint (Critical)

The headline fix is a critical pre-authentication server-side request forgery in a GHES upload endpoint. Input parameters accepted by the endpoint were not strictly validated, allowing a network-adjacent attacker — with no authentication required — to craft upload requests that caused the GHES server to issue internal HTTP calls to attacker-controlled destinations and internal addresses. Because the request originates from the GHES appliance itself, the attacker can reach internal services on the same network segment, the appliance's own loopback management interfaces, and cloud metadata endpoints (e.g. 169.254.169.254 on AWS/Azure/GCP-hosted instances), potentially exfiltrating instance credentials, IAM role tokens, environment configuration, and other secrets accessible to the appliance.

The vulnerability is a general-purpose SSRF primitive: response data and timing differences can be observed to enumerate internal services and to perform blind SSRF against authenticated internal APIs. Reported via the GitHub Bug Bounty program. GitHub mitigated by tightening input validation, applying destination allow-listing to the endpoint, and preventing the upload path from emitting arbitrary outbound HTTP requests.

## CVE-2026-43284 & CVE-2026-43500 — "Dirty Frag" Kernel LPEs (High)

GHES 3.20.3 also ships an updated bundled Linux kernel that fixes two high-severity local privilege-escalation flaws collectively branded "Dirty Frag" — one in the IPsec ESP (XFRM) subsystem (CVE-2026-43284) and one in the RxRPC networking subsystem (CVE-2026-43500). The Dirty Frag family of bugs abuses fragmentation/coalescing logic in the kernel networking path to drive an out-of-bounds page-cache write, allowing a local unprivileged user with shell access on the appliance to corrupt kernel memory and gain root.

In the GHES context this is most dangerous on multi-tenant or large-team appliances where multiple internal users, CI runners, or automated processes have shell access (admin shell, support-bundle generation contexts, scripted maintenance). A low-privileged foothold (e.g. an attacker who chained the SSRF, leveraged a separate webshell, or compromised a legitimate operator account) can be reliably escalated to root, granting full control over the underlying OS, the entire Git data set, all repository secrets, and all customer source code stored on the appliance.

## CVE-2026-5921 & CVE-2026-8606 — Additional Hardening

GHES 3.20.3 also rolls in fixes carried over from earlier 3.20.x updates: a timing side-channel in the notebook viewer that could leak environment variables to an attacker (CVE-2026-5921), and an internal packages endpoint that could be abused for unauthenticated SSRF when private mode is disabled (CVE-2026-8606). Both were reported through the GitHub Bug Bounty program.

## GPG Signing Key Rotation (Operational Hard Gate)

As part of this release, GitHub has revoked the previous GPG signing key for GHES release packages and signed 3.20.3 (and all subsequent images) with a new key. Administrators must run GitHub's official key-rotation script/procedure to install the new trusted public key on every appliance before attempting the 3.20.3 upgrade. Skipping the rotation step will cause the appliance's signature verification to fail and the upgrade to be blocked — delaying deployment of the SSRF and kernel LPE fixes.

## Operational Impact and Recommended Posture

Any GHES appliance reachable from a less-trusted network is at risk of pre-auth SSRF exploitation; if shell access is shared by multiple teams, the chained SSRF -> credential theft -> remote authenticated foothold -> kernel LPE -> root path is realistic. GitHub recommends that all GHES 3.20.x customers prioritize this upgrade after completing the GPG key rotation, and revisit network segmentation on upload, notebook, and packages endpoints. There is no public PoC at time of disclosure and no confirmed in-the-wild exploitation; severity is driven by the network reachability, lack of authentication, and proven escalation path on the same appliance.

## MITRE ATT&CK

- T1595 Active Scanning
- T1590 Gather Victim Network Information
- T1587 Develop Capabilities
- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1203 Exploitation for Client Execution
- T1059 Command and Scripting Interpreter
- T1098 Account Manipulation
- T1543 Create or Modify System Process
- T1068 Exploitation for Privilege Escalation
- T1548 Abuse Elevation Control Mechanism
- T1070 Indicator Removal
- T1553 Subvert Trust Controls
- T1528 Steal Application Access Token
- T1552 Unsecured Credentials
- T1526 Cloud Service Discovery
- T1580 Cloud Infrastructure Discovery
- T1046 Network Service Discovery
- T1550 Use Alternate Authentication Material
- T1602 Data from Configuration Repository
- T1213 Data from Information Repositories
- T1071 Application Layer Protocol
- T1567 Exfiltration Over Web Service
- T1565 Data Manipulation

## Sources

- [Cyber Security News — GitHub Enterprise Server 3.20.3 Released With Fixes for Critical Vulnerabilities](https://cybersecuritynews.com/github-enterprise-server-3-20-3/)
- [GitHub Enterprise Server Release Notes (3.20 series)](https://docs.github.com/en/enterprise-server@3.20/admin/release-notes)
- [GitHub Security Advisories — GHES 3.20.3](https://github.com/advisories?query=GHES+3.20.3)
- [NVD — CVE-2026-9312 (GHES Pre-Auth SSRF)](https://nvd.nist.gov/vuln/detail/CVE-2026-9312)
- [NVD — CVE-2026-43284 (Linux Kernel XFRM ESP LPE — Dirty Frag)](https://nvd.nist.gov/vuln/detail/CVE-2026-43284)
- [NVD — CVE-2026-43500 (Linux Kernel RxRPC LPE — Dirty Frag)](https://nvd.nist.gov/vuln/detail/CVE-2026-43500)
- [NVD — CVE-2026-5921 (GHES Notebook Viewer Timing Side-Channel)](https://nvd.nist.gov/vuln/detail/CVE-2026-5921)
- [NVD — CVE-2026-8606 (GHES Internal Packages Endpoint SSRF)](https://nvd.nist.gov/vuln/detail/CVE-2026-8606)
- [GitHub Bug Bounty Program](https://bounty.github.com/)
- [GitHub Docs — Upgrading GitHub Enterprise Server (signing key rotation)](https://docs.github.com/en/enterprise-server@3.20/admin/upgrading)
- [MITRE ATT&CK — T1190 Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190/)
- [MITRE ATT&CK — T1068 Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0605
