Skip to content

Commit b5d50bf

Browse files
authored
Remove CVE-2026-12373 note from four GHES patch release notes (#61994)
1 parent 4902e4e commit b5d50bf

4 files changed

Lines changed: 0 additions & 8 deletions

File tree

data/release-notes/enterprise-server/3-18/11.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,8 +9,6 @@ sections:
99
**MEDIUM**: An attacker could gain unintended access to an organization's runner management by directing a user to authorize an OAuth app whose requested manage_runners:org scope was not displayed on the authorization consent screen. GitHub has requested CVE ID [CVE-2026-9106](https://www.cve.org/cverecord?id=CVE-2026-9106) for this vulnerability, which was reported via the [GitHub Bug Bounty](https://bounty.github.com/) program.
1010
- |
1111
**MEDIUM**: An authenticated GHES user could read source code from private repositories they did not have access to by supplying a cross-repository comparison range to the Copilot pull request description diff summary endpoint, which did not verify the user's permission to view the target repository. GitHub has requested CVE ID [CVE-2026-9132](https://www.cve.org/cverecord?id=CVE-2026-9132) for this vulnerability, which was reported via the [GitHub Bug Bounty program](https://bounty.github.com/).
12-
- |
13-
**MEDIUM**: An attacker who could execute code within a Copilot coding agent session, for example through a malicious dependency or repository setup steps, could use the agent's server-to-server token to create, modify, or delete releases and release assets in that repository via the REST API, exceeding the agent's documented push-only restriction. GitHub has requested CVE ID [CVE-2026-12373](https://www.cve.org/cverecord?id=CVE-2026-12373) for this vulnerability, which was reported via the [GitHub Bug Bounty program](https://bounty.github.com/).
1412
- |
1513
**MEDIUM**: An attacker could execute arbitrary JavaScript in a victim's browser on a GitHub Enterprise Server instance by creating a discussion in the Q\&A category with a crafted title that breaks out of the JSON-LD structured-data script block when a comment is marked as the answer. To mitigate this issue, GitHub has updated the rendering of JSON-LD structured data in discussions to properly escape user-controlled input. GitHub has requested CVE ID [CVE-2026-10585](https://www.cve.org/cverecord?id=CVE-2026-10585) for this vulnerability, which was reported via the [GitHub Bug Bounty](https://bounty.github.com/) program.
1614
- |

data/release-notes/enterprise-server/3-19/8.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,8 +9,6 @@ sections:
99
**MEDIUM**: An attacker could gain unintended access to an organization's runner management by directing a user to authorize an OAuth app whose requested manage_runners:org scope was not displayed on the authorization consent screen. GitHub has requested CVE ID [CVE-2026-9106](https://www.cve.org/cverecord?id=CVE-2026-9106) for this vulnerability, which was reported via the [GitHub Bug Bounty](https://bounty.github.com/) program.
1010
- |
1111
**MEDIUM**: An authenticated GHES user could read source code from private repositories they did not have access to by supplying a cross-repository comparison range to the Copilot pull request description diff summary endpoint, which did not verify the user's permission to view the target repository. GitHub has requested CVE ID [CVE-2026-9132](https://www.cve.org/cverecord?id=CVE-2026-9132) for this vulnerability, which was reported via the [GitHub Bug Bounty program](https://bounty.github.com/).
12-
- |
13-
**MEDIUM**: An attacker who could execute code within a Copilot coding agent session, for example through a malicious dependency or repository setup steps, could use the agent's server-to-server token to create, modify, or delete releases and release assets in that repository via the REST API, exceeding the agent's documented push-only restriction. GitHub has requested CVE ID [CVE-2026-12373](https://www.cve.org/cverecord?id=CVE-2026-12373) for this vulnerability, which was reported via the [GitHub Bug Bounty program](https://bounty.github.com/).
1412
- |
1513
**MEDIUM**: An attacker could execute arbitrary JavaScript in a victim's browser on a GitHub Enterprise Server instance by creating a discussion in the Q\&A category with a crafted title that breaks out of the JSON-LD structured-data script block when a comment is marked as the answer. To mitigate this issue, GitHub has updated the rendering of JSON-LD structured data in discussions to properly escape user-controlled input. GitHub has requested CVE ID [CVE-2026-10585](https://www.cve.org/cverecord?id=CVE-2026-10585) for this vulnerability, which was reported via the [GitHub Bug Bounty](https://bounty.github.com/) program.
1614
- |

data/release-notes/enterprise-server/3-20/4.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,8 +9,6 @@ sections:
99
**MEDIUM**: An attacker could gain unintended access to an organization's runner management by directing a user to authorize an OAuth app whose requested manage_runners:org scope was not displayed on the authorization consent screen. GitHub has requested CVE ID [CVE-2026-9106](https://www.cve.org/cverecord?id=CVE-2026-9106) for this vulnerability, which was reported via the [GitHub Bug Bounty](https://bounty.github.com/) program.
1010
- |
1111
**MEDIUM**: An authenticated GHES user could read source code from private repositories they did not have access to by supplying a cross-repository comparison range to the Copilot pull request description diff summary endpoint, which did not verify the user's permission to view the target repository. GitHub has requested CVE ID [CVE-2026-9132](https://www.cve.org/cverecord?id=CVE-2026-9132) for this vulnerability, which was reported via the [GitHub Bug Bounty program](https://bounty.github.com/).
12-
- |
13-
**MEDIUM**: An attacker who could execute code within a Copilot coding agent session, for example through a malicious dependency or repository setup steps, could use the agent's server-to-server token to create, modify, or delete releases and release assets in that repository via the REST API, exceeding the agent's documented push-only restriction. GitHub has requested CVE ID [CVE-2026-12373](https://www.cve.org/cverecord?id=CVE-2026-12373) for this vulnerability, which was reported via the [GitHub Bug Bounty program](https://bounty.github.com/).
1412
- |
1513
**MEDIUM**: An attacker could execute arbitrary JavaScript in a victim's browser on a GitHub Enterprise Server instance by creating a discussion in the Q\&A category with a crafted title that breaks out of the JSON-LD structured-data script block when a comment is marked as the answer. To mitigate this issue, GitHub has updated the rendering of JSON-LD structured data in discussions to properly escape user-controlled input. GitHub has requested CVE ID [CVE-2026-10585](https://www.cve.org/cverecord?id=CVE-2026-10585) for this vulnerability, which was reported via the [GitHub Bug Bounty](https://bounty.github.com/) program.
1614
- |

data/release-notes/enterprise-server/3-21/2.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,8 +7,6 @@ sections:
77
**MEDIUM**: An attacker with site administrator privileges could extract arbitrary data from the instance's database, including user password hashes, by exploiting a blind SQL injection vulnerability in the `dependenciesPrefers` argument of the `dependencyGraphManifests` GraphQL field. This vulnerability affected instances with the dependency graph enabled and was reported via the GitHub Bug Bounty program.
88
- |
99
**MEDIUM**: An attacker could gain unintended access to an organization's runner management by directing a user to authorize an OAuth app whose requested manage_runners:org scope was not displayed on the authorization consent screen. GitHub has requested CVE ID [CVE-2026-9106](https://www.cve.org/cverecord?id=CVE-2026-9106) for this vulnerability, which was reported via the [GitHub Bug Bounty](https://bounty.github.com/) program.
10-
- |
11-
**MEDIUM**: An attacker who could execute code within a Copilot coding agent session, for example through a malicious dependency or repository setup steps, could use the agent's server-to-server token to create, modify, or delete releases and release assets in that repository via the REST API, exceeding the agent's documented push-only restriction. GitHub has requested CVE ID [CVE-2026-12373](https://www.cve.org/cverecord?id=CVE-2026-12373) for this vulnerability, which was reported via the [GitHub Bug Bounty program](https://bounty.github.com/).
1210
- |
1311
GitHub has updated `dnsmasq` to fix the following vulnerabilities: CVE-2026-4891, CVE-2026-4890, CVE-2026-4892, CVE-2026-4893, CVE-2026-5172, CVE-2026-2291.
1412
- |

0 commit comments

Comments
 (0)