GitHub Product Security Update Advisory (CVE-2025-3509)
Overview
We have released security updates to fix vulnerabilities in GitHub products. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2025-3509
Enterprise Server Versions: 3.13.14 and earlier
Enterprise Server Versions: 3.14.11 and earlier
Enterprise Server Versions: 3.15.6 and earlier
Enterprise Server Versions: 3.16.2 and earlier
Resolved Vulnerabilities
Remote code execution vulnerability in Enterprise Server (CVE-2025-3509)
Vulnerability Patches
Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2025-3509
Enterprise Server version: 3.13.14
Enterprise Server version: 3.14.11
Enterprise Server version: 3.15.6
Enterprise Server version: 3.16.2
References
[1] Enterprise Server 3.13.14
https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.14
[2] Enterprise Server 3.14.11
https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.11
[3] Enterprise Server 3.15.6
https://docs.github.com/en/enterprise-server@3.15/admin/release-notes#3.15.6
[4] Enterprise Server 3.16.2
https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.2