What is CVE-2026-15996?
A denial of service vulnerability was identified in GitHub Enterprise Server allowing an unauthenticated attacker to cause excessive CPU consumption and exhaust request-handling worker processes by sending a crafted form-encoded HTTP POST request with deeply nested parameters. It is recommended to apply the security update.
Azərbaycanca: GitHub Enterprise Server-də autentifikasiya olunmamış təcavüzkarın dərin yuvalanmış parametrlərlə xüsusi hazırlanmış HTTP POST sorğusu göndərərək həddindən artıq CPU istehlakına səbəb olduğu xidmət rəddi (DoS) boşluğu aşkar edilib. Bu zəiflik uğurla istismar edildikdə, serverin sorğu emal edən işçi prosesləri (worker processes) tükənə bilər. Təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ1
Does exploiting CVE-2026-15996 require authentication on GitHub Enterprise Server?
No, this vulnerability can be exploited by an unauthenticated attacker.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.