Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-7541

29
FAUCET Score

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by sending crafted requests with deeply nested JSON payloads to an unauthenticated API endpoint. The endpoint parsed user-controlled JSON request bodies without size or depth limits, causing excessive CPU and memory consumption. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.2, 3.19.6, 3.18.9, 3.17.15, and 3.16.18. This vulnerability was reported via the GitHub Bug Bounty program.

First published: May 7, 2026Last modified: May 8, 2026

Impacted Technologies

VendorProductVersion(s)CPE
< 3.16.18CPE matchmatch criteria
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
>= 3.17.0, < 3.17.15CPE matchmatch criteria
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
>= 3.18.0, < 3.18.9CPE matchmatch criteria
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
>= 3.19.0, < 3.19.6CPE matchmatch criteria
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*
>= 3.20.0, < 3.20.2CPE matchmatch criteria
cpe:2.3:a:github:enterprise_server:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.3MEDIUM

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
HIGH
Exploit Maturity
UNREPORTED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.39%
Probability of exploitation in next 30 days
EPSS Percentile
31.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0039 is in the 11th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

docs.github.com / en/[email protected]/admin/release-notes
Release NotesVendor Advisory
docs.github.com / en/[email protected]/admin/release-notes
Release NotesVendor Advisory
docs.github.com / en/[email protected]/admin/release-notes
Release NotesVendor Advisory
docs.github.com / en/[email protected]/admin/release-notes
Release NotesVendor Advisory
docs.github.com / en/[email protected]/admin/release-notes
Release NotesVendor Advisory