Количество 384 790
Количество 384 790
CVE-2026-58438
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
CVE-2026-58437
Repository Visibility Manipulation via Git Push Options
CVE-2026-58436
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
CVE-2026-58435
Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-58434
Private Repository Metadata Remains Accessible After Access Revocation
CVE-2026-58433
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
CVE-2026-58432
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
CVE-2026-58431
Public-only API token restriction is not enforced on team API routes
CVE-2026-5842
A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 0.3.75 is sufficient to resolve this issue. It is suggested to upgrade the affected component.
CVE-2026-58429
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CVE-2026-58428
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
CVE-2026-58427
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
CVE-2026-58426
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
CVE-2026-58425
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
CVE-2026-58424
Permanent Fork PR Workflow Approval Gate Bypass
CVE-2026-58423
LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
CVE-2026-58422
Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
CVE-2026-58421
Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
CVE-2026-58420
Local File Inclusion via file:// URI in Migration Restore
CVE-2026-5841
A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-58438 Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access | CVSS3: 7.5 | 0% Низкий | 20 дней назад | |
CVE-2026-58437 Repository Visibility Manipulation via Git Push Options | CVSS3: 7.1 | 0% Низкий | 20 дней назад | |
CVE-2026-58436 ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests | CVSS3: 7.5 | 0% Низкий | 20 дней назад | |
CVE-2026-58435 Gitea LFS Deploy-Key Privilege Escalation | CVSS3: 5.4 | 0% Низкий | 20 дней назад | |
CVE-2026-58434 Private Repository Metadata Remains Accessible After Access Revocation | CVSS3: 7.5 | 0% Низкий | 20 дней назад | |
CVE-2026-58433 Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting | CVSS3: 9.1 | 0% Низкий | 20 дней назад | |
CVE-2026-58432 Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea | CVSS3: 5.9 | 0% Низкий | 20 дней назад | |
CVE-2026-58431 Public-only API token restriction is not enforced on team API routes | CVSS3: 4.3 | 0% Низкий | 20 дней назад | |
CVE-2026-5842 A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 0.3.75 is sufficient to resolve this issue. It is suggested to upgrade the affected component. | CVSS3: 7.3 | 0% Низкий | 5 месяцев назад | |
CVE-2026-58429 Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints | CVSS3: 4.9 | 0% Низкий | 20 дней назад | |
CVE-2026-58428 Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) | CVSS3: 6.5 | 0% Низкий | 20 дней назад | |
CVE-2026-58427 Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 | CVSS3: 7.5 | 0% Низкий | 20 дней назад | |
CVE-2026-58426 Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write | CVSS3: 9.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-58425 OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) | CVSS3: 4.3 | 0% Низкий | 20 дней назад | |
CVE-2026-58424 Permanent Fork PR Workflow Approval Gate Bypass | CVSS3: 8.9 | 0% Низкий | 2 месяца назад | |
CVE-2026-58423 LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories | CVSS3: 7.7 | 1% Низкий | 2 месяца назад | |
CVE-2026-58422 Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts | CVSS3: 9.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-58421 Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-58420 Local File Inclusion via file:// URI in Migration Restore | CVSS3: 4.4 | 0% Низкий | 20 дней назад | |
CVE-2026-5841 A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. | CVSS3: 7.3 | 1% Низкий | 5 месяцев назад |
Уязвимостей на страницу