security1 publisher
GitHub Enterprise Server's notebook viewer leaked secrets to attackers who measured response times
GitHub patched CVE-2026-77987, a GitHub Enterprise Server flaw that let an unauthenticated attacker read instance secrets by timing notebook viewer responses. The secrets could yield remote code execution, and with private mode off the attack needed no login.
Publishers:docs.github.com
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−15
- Incentives40
- Confidence60