Search
Search Results (135 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-58445 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API | ||||
| CVE-2026-57894 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration | ||||
| CVE-2026-58314 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| Two SSRF findings in Gitea 1.26.2 | ||||
| CVE-2026-58420 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| Local File Inclusion via file:// URI in Migration Restore | ||||
| CVE-2026-58442 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| Repository migration SSRF via multi-answer DNS allow-list bypass | ||||
| CVE-2026-58444 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents | ||||
| CVE-2026-59765 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata | ||||
| CVE-2026-58417 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| REST API exposes organization membership of private organizations to public | ||||
| CVE-2026-58425 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) | ||||
| CVE-2026-58428 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) | ||||
| CVE-2026-58429 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints | ||||
| CVE-2026-58431 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| Public-only API token restriction is not enforced on team API routes | ||||
| CVE-2026-58432 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea | ||||
| CVE-2026-58433 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting | ||||
| CVE-2026-58435 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| Gitea LFS Deploy-Key Privilege Escalation | ||||
| CVE-2026-58436 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests | ||||
| CVE-2026-58438 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access | ||||
| CVE-2026-58440 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`) | ||||
| CVE-2026-58441 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL | ||||
| CVE-2026-58508 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | ||||