Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48624
Total
3905
Critical
14425
High
14119
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-58444 | UNKNOWN | — | Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents | Aug 13, 2026 |
| CVE-2026-58443 | UNKNOWN | — | Public-only repository tokens can update private PR head branches | Aug 13, 2026 |
| CVE-2026-58442 | UNKNOWN | — | Repository migration SSRF via multi-answer DNS allow-list bypass | Aug 13, 2026 |
| CVE-2026-58441 | UNKNOWN | — | SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL | Aug 13, 2026 |
| CVE-2026-58440 | UNKNOWN | — | Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in … | Aug 13, 2026 |
| CVE-2026-58439 | UNKNOWN | — | Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag | Aug 13, 2026 |
| CVE-2026-58438 | UNKNOWN | — | Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access | Aug 13, 2026 |
| CVE-2026-58437 | UNKNOWN | — | Repository Visibility Manipulation via Git Push Options | Aug 13, 2026 |
| CVE-2026-58436 | UNKNOWN | — | ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests | Aug 13, 2026 |
| CVE-2026-58435 | UNKNOWN | — | Gitea LFS Deploy-Key Privilege Escalation | Aug 13, 2026 |
| CVE-2026-58434 | UNKNOWN | — | Private Repository Metadata Remains Accessible After Access Revocation | Aug 13, 2026 |
| CVE-2026-58433 | UNKNOWN | — | Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting | Aug 13, 2026 |
| CVE-2026-58432 | UNKNOWN | — | Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in … | Aug 13, 2026 |
| CVE-2026-58431 | UNKNOWN | — | Public-only API token restriction is not enforced on team API routes | Aug 13, 2026 |
| CVE-2026-58429 | UNKNOWN | — | Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints | Aug 13, 2026 |
| CVE-2026-58428 | UNKNOWN | — | Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) | Aug 13, 2026 |
| CVE-2026-58427 | UNKNOWN | — | Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 | Aug 13, 2026 |
| CVE-2026-58425 | UNKNOWN | — | OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) | Aug 13, 2026 |
| CVE-2026-58420 | UNKNOWN | — | Local File Inclusion via file:// URI in Migration Restore | Aug 13, 2026 |
| CVE-2026-58417 | UNKNOWN | — | REST API exposes organization membership of private organizations to public | Aug 13, 2026 |
| CVE-2026-58416 | HIGH | 7.1 | Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) | Aug 13, 2026 |
| CVE-2026-58314 | UNKNOWN | — | Two SSRF findings in Gitea 1.26.2 | Aug 13, 2026 |
| CVE-2026-57897 | MEDIUM | 6.5 | Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs | Aug 13, 2026 |
| CVE-2026-57894 | UNKNOWN | — | Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration | Aug 13, 2026 |
| CVE-2026-57886 | UNKNOWN | — | Cross-repository issue/comment attachment re-linking can expose private attachment content | Aug 13, 2026 |