Vulnerabilities (CVE)

Total 398446 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-56654 2026-08-26 N/A 9.8 CRITICAL
Privilege Escalation via Access Token Scope Escalation in API
CVE-2026-55984 2026-08-26 N/A 2.7 LOW
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
CVE-2026-54481 2026-08-26 N/A 7.5 HIGH
Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)
CVE-2026-55987 2026-08-26 N/A 8.1 HIGH
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
CVE-2026-24791 2026-08-26 N/A 8.1 HIGH
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
CVE-2026-58425 2026-08-26 N/A 4.3 MEDIUM
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
CVE-2026-58439 2026-08-26 N/A 8.1 HIGH
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
CVE-2026-57897 2026-08-26 N/A 6.5 MEDIUM
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
CVE-2026-58511 2026-08-26 N/A 2.7 LOW
Webhook Authorization Header Returned in Plaintext via API
CVE-2026-58445 2026-08-26 N/A 2.7 LOW
Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
CVE-2026-58432 2026-08-26 N/A 5.9 MEDIUM
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
CVE-2026-57894 2026-08-26 N/A 8.5 HIGH
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
CVE-2026-58442 2026-08-26 N/A 6.5 MEDIUM
Repository migration SSRF via multi-answer DNS allow-list bypass
CVE-2026-56755 2026-08-26 N/A 6.2 MEDIUM
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
CVE-2026-56657 2026-08-26 N/A 6.2 MEDIUM
Gitea SSH Key Parser Denial of Service
CVE-2026-58433 2026-08-26 N/A 9.1 CRITICAL
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
CVE-2026-58507 2026-08-26 N/A 5.3 MEDIUM
Private Repository Existence Disclosure via go-get Meta Endpoint
CVE-2026-58510 2026-08-26 N/A 4.3 MEDIUM
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
CVE-2026-58441 2026-08-26 N/A 6.3 MEDIUM
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
CVE-2026-59765 2026-08-26 N/A 7.5 HIGH
SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata