CVE-2026-7541 Details
Description
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by sending crafted requests with deeply nested JSON payloads to an unauthenticated API endpoint. The endpoint parsed user-controlled JSON request bodies without size or depth limits, causing excessive CPU and memory consumption. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.2, 3.19.6, 3.18.9, 3.17.15, and 3.16.18. This vulnerability was reported via the GitHub Bug Bounty program.
A denial-of-service vulnerability exists in GitHub Enterprise Server versions prior to 3.21. An unauthenticated attacker can disrupt service by sending crafted requests with deeply nested JSON payloads to an unauthenticated API endpoint. The endpoint parses user-controlled JSON request bodies without size or depth limits, leading to excessive CPU and memory consumption. This vulnerability was reported through the GitHub Bug Bounty program.
To address this vulnerability, GitHub Enterprise Server administrators should upgrade to version 3.20.2 or later. Instructions for upgrading can be found in the GitHub Enterprise Server release notes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.github.com/en/[email protected]/admin/release-notes#3.16.18 | [email protected] | Release NotesVendor Advisory |
| https://docs.github.com/en/[email protected]/admin/release-notes#3.17.15 | [email protected] | Release NotesVendor Advisory |
| https://docs.github.com/en/[email protected]/admin/release-notes#3.18.9 | [email protected] | Release NotesVendor Advisory |
| https://docs.github.com/en/[email protected]/admin/release-notes#3.19.6 | [email protected] | Release NotesVendor Advisory |
| https://docs.github.com/en/[email protected]/admin/release-notes#3.20.2 | [email protected] | Release NotesVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| github enterprise server | < 3.16.18 >= 3.17.0, < 3.17.15 >= 3.18.0, < 3.18.9 >= 3.19.0, < 3.19.6 >= 3.20.0, < 3.20.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | Initial Analysis | [email protected] |
| May 7, 2026 | New CVE Received | [email protected] |