Vulnerabilities (CVE)

Total 398446 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-56443 2026-08-26 N/A 9.6 CRITICAL
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
CVE-2026-24059 2026-08-26 N/A 6.5 MEDIUM
The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked read:user-scoped token can therefore mint a registration token and register a malicious Actions runner that executes workflow jobs with access to repository secrets and source code.
CVE-2026-58420 2026-08-26 N/A 4.4 MEDIUM
Local File Inclusion via file:// URI in Migration Restore
CVE-2026-56750 2026-08-26 N/A 9.1 CRITICAL
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
CVE-2026-58435 2026-08-26 N/A 5.4 MEDIUM
Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-58416 2026-08-26 N/A 7.1 HIGH
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
CVE-2026-58437 2026-08-26 N/A 7.1 HIGH
Repository Visibility Manipulation via Git Push Options
CVE-2026-23603 2026-08-26 N/A 3.1 LOW
Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
CVE-2026-55982 2026-08-26 N/A 9.1 CRITICAL
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
CVE-2026-58438 2026-08-26 N/A 7.5 HIGH
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
CVE-2026-58428 2026-08-26 N/A 6.5 MEDIUM
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
CVE-2026-58429 2026-08-26 N/A 4.9 MEDIUM
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CVE-2026-58508 2026-08-26 N/A 9.1 CRITICAL
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
CVE-2026-58444 2026-08-26 N/A 4.3 MEDIUM
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
CVE-2026-58431 2026-08-26 N/A 4.3 MEDIUM
Public-only API token restriction is not enforced on team API routes
CVE-2026-58314 2026-08-26 N/A 7.7 HIGH
Two SSRF findings in Gitea 1.26.2
CVE-2026-50105 2026-08-26 N/A 4.3 MEDIUM
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
CVE-2026-66300 2026-08-26 N/A 5.0 MEDIUM
SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An attacker can inject arbitrary JavaScript which will execute upon a target user navigating to a crafted, malicious link. Fixed in 10.12.2 and 10.9.3.
CVE-2026-73669 2026-08-26 N/A 7.3 HIGH
The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network interfaces without authentication. An unauthenticated attacker with network access to the MQTT service on a vulnerable system can read data and control connected lights. Fixed in 1.77.2071318010.
CVE-2026-75933 2026-08-26 N/A 7.3 HIGH
Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and styles option. Injected script is executed in the context of any visiting user's domain.