CVE-2026-4296 Details
Description
An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. An attacker with knowledge of a first-party OAuth application's registered callback URL could craft a malicious authorization link that, when clicked by a victim, would redirect the OAuth authorization code to an attacker-controlled domain. This could allow the attacker to gain unauthorized access to the victim's account with the scopes granted to the OAuth application. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, 3.14.26. This vulnerability was reported via the GitHub Bug Bounty program.
A vulnerability allowing an OAuth redirect URI validation bypass has been identified in GitHub Enterprise Server. This issue affects all versions prior to 3.21. The vulnerability arises from an incorrect regular expression validation, which enables an attacker to manipulate the OAuth authorization process. By crafting a malicious authorization link that redirects to an attacker-controlled domain, unauthorized access to the victim's account could be gained, exploiting the scopes granted to the OAuth application. The vulnerability requires knowledge of the target application's registered callback URL and could be exploited by redirecting the OAuth authorization code to an attacker-controlled domain, potentially leading to unauthorized access to private repositories.
Users can upgrade to GitHub Enterprise Server versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, or 3.14.26 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.github.com/en/[email protected]/admin/release-notes#3.14.26 | [email protected] | Release NotesVendor Advisory |
| https://docs.github.com/en/[email protected]/admin/release-notes#3.15.21 | [email protected] | Release NotesVendor Advisory |
| https://docs.github.com/en/[email protected]/admin/release-notes#3.16.17 | [email protected] | Release NotesVendor Advisory |
| https://docs.github.com/en/[email protected]/admin/release-notes#3.17.14 | [email protected] | Release NotesVendor Advisory |
| https://docs.github.com/en/[email protected]/admin/release-notes#3.18.8 | [email protected] | Release NotesVendor Advisory |
| https://docs.github.com/en/[email protected]/admin/release-notes#3.19.5 | [email protected] | Release NotesVendor Advisory |
| https://docs.github.com/en/[email protected]/admin/release-notes#3.20.1 | [email protected] | Release NotesVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-185 | Incorrect Regular Expression | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| github enterprise server | < 3.14.26 >= 3.15.0, < 3.15.21 >= 3.16.0, < 3.16.17 >= 3.17.0, < 3.17.14 >= 3.18.0, < 3.18.8 >= 3.19.0, < 3.19.5 3.20.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Initial Analysis | [email protected] |
| Apr 21, 2026 | New CVE Received | [email protected] |