Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47882
Total
3850
Critical
14243
High
13921
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-59765 | UNKNOWN | — | SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata | Aug 13, 2026 |
| CVE-2026-59763 | MEDIUM | 4.3 | Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads | Aug 13, 2026 |
| CVE-2026-59109 | HIGH | 8.8 | SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, … | Aug 13, 2026 |
| CVE-2026-58511 | LOW | 2.7 | Webhook Authorization Header Returned in Plaintext via API | Aug 13, 2026 |
| CVE-2026-58510 | MEDIUM | 4.3 | GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private | Aug 13, 2026 |
| CVE-2026-58508 | UNKNOWN | — | Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | Aug 13, 2026 |
| CVE-2026-58507 | UNKNOWN | — | Private Repository Existence Disclosure via go-get Meta Endpoint | Aug 13, 2026 |
| CVE-2026-58445 | UNKNOWN | — | Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API | Aug 13, 2026 |
| CVE-2026-58444 | UNKNOWN | — | Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents | Aug 13, 2026 |
| CVE-2026-58443 | UNKNOWN | — | Public-only repository tokens can update private PR head branches | Aug 13, 2026 |
| CVE-2026-58442 | UNKNOWN | — | Repository migration SSRF via multi-answer DNS allow-list bypass | Aug 13, 2026 |
| CVE-2026-58441 | UNKNOWN | — | SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL | Aug 13, 2026 |
| CVE-2026-58440 | UNKNOWN | — | Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in … | Aug 13, 2026 |
| CVE-2026-58439 | UNKNOWN | — | Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag | Aug 13, 2026 |
| CVE-2026-58438 | UNKNOWN | — | Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access | Aug 13, 2026 |
| CVE-2026-58437 | UNKNOWN | — | Repository Visibility Manipulation via Git Push Options | Aug 13, 2026 |
| CVE-2026-58436 | UNKNOWN | — | ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests | Aug 13, 2026 |
| CVE-2026-58435 | UNKNOWN | — | Gitea LFS Deploy-Key Privilege Escalation | Aug 13, 2026 |
| CVE-2026-58434 | UNKNOWN | — | Private Repository Metadata Remains Accessible After Access Revocation | Aug 13, 2026 |
| CVE-2026-58433 | UNKNOWN | — | Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting | Aug 13, 2026 |
| CVE-2026-58432 | UNKNOWN | — | Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in … | Aug 13, 2026 |
| CVE-2026-58431 | UNKNOWN | — | Public-only API token restriction is not enforced on team API routes | Aug 13, 2026 |
| CVE-2026-58429 | UNKNOWN | — | Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints | Aug 13, 2026 |
| CVE-2026-58428 | UNKNOWN | — | Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) | Aug 13, 2026 |
| CVE-2026-58427 | UNKNOWN | — | Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 | Aug 13, 2026 |