Total
398446 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-56654 | 2026-08-26 | N/A | 9.8 CRITICAL | ||
| Privilege Escalation via Access Token Scope Escalation in API | |||||
| CVE-2026-55984 | 2026-08-26 | N/A | 2.7 LOW | ||
| Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service | |||||
| CVE-2026-54481 | 2026-08-26 | N/A | 7.5 HIGH | ||
| Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295) | |||||
| CVE-2026-55987 | 2026-08-26 | N/A | 8.1 HIGH | ||
| OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) | |||||
| CVE-2026-24791 | 2026-08-26 | N/A | 8.1 HIGH | ||
| Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes | |||||
| CVE-2026-58425 | 2026-08-26 | N/A | 4.3 MEDIUM | ||
| OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) | |||||
| CVE-2026-58439 | 2026-08-26 | N/A | 8.1 HIGH | ||
| Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag | |||||
| CVE-2026-57897 | 2026-08-26 | N/A | 6.5 MEDIUM | ||
| Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs | |||||
| CVE-2026-58511 | 2026-08-26 | N/A | 2.7 LOW | ||
| Webhook Authorization Header Returned in Plaintext via API | |||||
| CVE-2026-58445 | 2026-08-26 | N/A | 2.7 LOW | ||
| Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API | |||||
| CVE-2026-58432 | 2026-08-26 | N/A | 5.9 MEDIUM | ||
| Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea | |||||
| CVE-2026-57894 | 2026-08-26 | N/A | 8.5 HIGH | ||
| Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration | |||||
| CVE-2026-58442 | 2026-08-26 | N/A | 6.5 MEDIUM | ||
| Repository migration SSRF via multi-answer DNS allow-list bypass | |||||
| CVE-2026-56755 | 2026-08-26 | N/A | 6.2 MEDIUM | ||
| Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload | |||||
| CVE-2026-56657 | 2026-08-26 | N/A | 6.2 MEDIUM | ||
| Gitea SSH Key Parser Denial of Service | |||||
| CVE-2026-58433 | 2026-08-26 | N/A | 9.1 CRITICAL | ||
| Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting | |||||
| CVE-2026-58507 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| Private Repository Existence Disclosure via go-get Meta Endpoint | |||||
| CVE-2026-58510 | 2026-08-26 | N/A | 4.3 MEDIUM | ||
| GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private | |||||
| CVE-2026-58441 | 2026-08-26 | N/A | 6.3 MEDIUM | ||
| SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL | |||||
| CVE-2026-59765 | 2026-08-26 | N/A | 7.5 HIGH | ||
| SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata | |||||
