Vulnerability Description
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When release notes were generated, the configuration file was parsed without a nesting depth limit, causing excessive resource consumption that could render the instance unresponsive. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.18, 3.18.12, 3.19.9, 3.20.5, and 3.21.3. This vulnerability was reported via the GitHub Bug Bounty program.
Related Weaknesses (CWE)
References
- https://docs.github.com/en/[email protected]/admin/release-notes#3.17.18
- https://docs.github.com/en/[email protected]/admin/release-notes#3.18.12
- https://docs.github.com/en/[email protected]/admin/release-notes#3.19.9
- https://docs.github.com/en/[email protected]/admin/release-notes#3.20.5
- https://docs.github.com/en/[email protected]/admin/release-notes#3.21.3
FAQ
What is CVE-2026-15007?
CVE-2026-15007 is a documented vulnerability. A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file c...
How severe is CVE-2026-15007?
CVSS scoring is not yet available for CVE-2026-15007. Check NVD for updates.
Is there a patch for CVE-2026-15007?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.