Back to Blog
CVE-2026-77987: GitHub's Notebook Viewer Could Expose Secrets Without Returning Them

CVE-2026-77987: GitHub's Notebook Viewer Could Expose Secrets Without Returning Them

Sythe Labs Team

A server does not have to return a secret in its response for an attacker to learn it.

GitHub's September 22 security release describes a critical vulnerability in GitHub Enterprise Server's notebook viewer. An attacker could make it contact internal services on the appliance, infer secrets from response timing, and use an extracted secret to obtain remote code execution. GitHub tracks the flaw as CVE-2026-77987. GitHub's release notes.

The missing check was the port.

The viewer validated a user-supplied URL's scheme and hostname, but did not validate its port. That allowed a request to reach another service on the same appliance while still passing the checks on the destination's other components. Advisory.

That distinction matters when reviewing features that fetch content on a user's behalf. An approved hostname can host several services with very different privileges. Permission to retrieve a document does not establish permission to contact every service listening on that machine.

The response body was hidden, but the timing remained observable. According to the advisory, those timing differences allowed secrets to be extracted character by character. A separate interaction with an internal service could then turn the stolen secret into code execution. Advisory.

For engineering teams, the lesson is to examine what an attacker can observe beyond the response body: timing, status changes, errors, and side effects can all carry information.

Exposure also depended on configuration. With private mode disabled, exploitation required no authentication. With private mode enabled, any authenticated user could attempt it. Private mode therefore changed the access requirement without eliminating the vulnerable path. GitHub's fix rejects notebook viewer URLs containing an explicit port. GitHub's release notes.

Administrators should check their GitHub Enterprise Server appliance version. The advisory lists fixes in 3.17.21, 3.18.15, 3.19.12, 3.20.8, 3.21.6, and 3.22.1. These are Enterprise Server releases; this advisory should not be presented as evidence that GitHub.com accounts are compromised. Affected and fixed releases.

After applying the appropriate update, verify the version running on the appliance and retain that evidence with the remediation record.

For your own applications, start with the features that retrieve remote content: notebook viewers, link previews, document converters, and importers. Trace the complete destination they can reach, including its port, and identify which internal services trust requests arriving from that process.

Sythe Seconds

Get the next insight in your inbox.

Research from our team, practical compliance guidance, and the latest from Sythe Labs. Straight to your inbox.

By subscribing, you agree to receive Sythe Seconds. Unsubscribe anytime. Privacy policy