Search
Search Results (87 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-58427 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 7.5 High |
| Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 | ||||
| CVE-2026-58429 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 4.9 Medium |
| Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints | ||||
| CVE-2026-58508 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 9.1 Critical |
| Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | ||||
| CVE-2026-58507 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 5.3 Medium |
| Private Repository Existence Disclosure via go-get Meta Endpoint | ||||
| CVE-2026-58445 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 2.7 Low |
| Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API | ||||
| CVE-2026-58444 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 4.3 Medium |
| Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents | ||||
| CVE-2026-58437 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 7.1 High |
| Repository Visibility Manipulation via Git Push Options | ||||
| CVE-2026-55986 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 5.4 Medium |
| Email Management API Bypasses ManageCredentials Feature Restrictions | ||||
| CVE-2026-58436 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 7.5 High |
| ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests | ||||
| CVE-2026-58435 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 5.4 Medium |
| Gitea LFS Deploy-Key Privilege Escalation | ||||
| CVE-2026-58431 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 4.3 Medium |
| Public-only API token restriction is not enforced on team API routes | ||||
| CVE-2026-58428 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 6.5 Medium |
| Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) | ||||
| CVE-2026-58425 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 4.3 Medium |
| OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) | ||||
| CVE-2026-58420 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 4.4 Medium |
| Local File Inclusion via file:// URI in Migration Restore | ||||
| CVE-2026-58417 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 7.5 High |
| REST API exposes organization membership of private organizations to public | ||||
| CVE-2026-57894 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 8.5 High |
| Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration | ||||
| CVE-2026-24059 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 6.5 Medium |
| The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked read:user-scoped token can therefore mint a registration token and register a malicious Actions runner that executes workflow jobs with access to repository secrets and source code. | ||||
| CVE-2026-23603 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 3.1 Low |
| Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim | ||||
| CVE-2026-58416 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 7.1 High |
| Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) | ||||
| CVE-2026-56657 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | 6.2 Medium |
| Gitea SSH Key Parser Denial of Service | ||||