GitHub security advisory (AV25-737) – Canadian Centre for Cyber Security

GitHub security advisory (AV25-737) – Canadian Centre for Cyber Security

GitHub has released security updates for several versions of GitHub Enterprise Server to fix known vulnerabilities, including CVE-2025-11892 which may have been exploited. Users are urged to review the advisories and apply patches immediately. #GitHubEnterpriseServer #CVE202511892

Keypoints

  • GitHub disclosed vulnerabilities affecting multiple versions of GitHub Enterprise Server.
  • Updates are available for versions 3.18.x, 3.17.x, 3.16.x, 3.15.x, and 3.14.x to address security issues.
  • CVE-2025-11892 is a critical vulnerability possibly exploited in the wild.
  • The Cyber Centre recommends prompt review and application of the security patches.
  • Users and administrators should follow the provided links for detailed update guidance.

Read More: https://www.cyber.gc.ca/en/alerts-advisories/github-security-advisory-av25-737