Количество 385 613
Количество 385 613
CVE-2026-58442
Repository migration SSRF via multi-answer DNS allow-list bypass
CVE-2026-58441
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
CVE-2026-58440
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)
CVE-2026-5843
The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a model's config.json specifies a model_file pointing to a Python file, MLX-LM uses importlib to load and execute it with no trust_remote_code gate or equivalent safety check. The MLX backend runs without sandboxing, resulting in arbitrary code execution on the Docker host as the Docker Desktop user. Any container on the Docker network can trigger this by calling the model-runner.docker.internal API to pull a malicious model from an attacker-controlled OCI registry and request inference.
CVE-2026-58439
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
CVE-2026-58438
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
CVE-2026-58437
Repository Visibility Manipulation via Git Push Options
CVE-2026-58436
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
CVE-2026-58435
Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-58434
Private Repository Metadata Remains Accessible After Access Revocation
CVE-2026-58433
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
CVE-2026-58432
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
CVE-2026-58431
Public-only API token restriction is not enforced on team API routes
CVE-2026-5842
A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 0.3.75 is sufficient to resolve this issue. It is suggested to upgrade the affected component.
CVE-2026-58429
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CVE-2026-58428
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
CVE-2026-58427
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
CVE-2026-58426
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
CVE-2026-58425
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
CVE-2026-58424
Permanent Fork PR Workflow Approval Gate Bypass
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-58442 Repository migration SSRF via multi-answer DNS allow-list bypass | CVSS3: 6.5 | 0% Низкий | 22 дня назад | |
CVE-2026-58441 SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL | CVSS3: 6.3 | 0% Низкий | 22 дня назад | |
CVE-2026-58440 Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`) | CVSS3: 6.8 | 0% Низкий | 22 дня назад | |
CVE-2026-5843 The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a model's config.json specifies a model_file pointing to a Python file, MLX-LM uses importlib to load and execute it with no trust_remote_code gate or equivalent safety check. The MLX backend runs without sandboxing, resulting in arbitrary code execution on the Docker host as the Docker Desktop user. Any container on the Docker network can trigger this by calling the model-runner.docker.internal API to pull a malicious model from an attacker-controlled OCI registry and request inference. | CVSS3: 8.2 | 0% Низкий | 3 месяца назад | |
CVE-2026-58439 Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag | CVSS3: 8.1 | 0% Низкий | 22 дня назад | |
CVE-2026-58438 Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access | CVSS3: 7.5 | 0% Низкий | 22 дня назад | |
CVE-2026-58437 Repository Visibility Manipulation via Git Push Options | CVSS3: 7.1 | 0% Низкий | 22 дня назад | |
CVE-2026-58436 ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests | CVSS3: 7.5 | 0% Низкий | 22 дня назад | |
CVE-2026-58435 Gitea LFS Deploy-Key Privilege Escalation | CVSS3: 5.4 | 0% Низкий | 22 дня назад | |
CVE-2026-58434 Private Repository Metadata Remains Accessible After Access Revocation | CVSS3: 7.5 | 0% Низкий | 22 дня назад | |
CVE-2026-58433 Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting | CVSS3: 9.1 | 0% Низкий | 22 дня назад | |
CVE-2026-58432 Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea | CVSS3: 5.9 | 0% Низкий | 22 дня назад | |
CVE-2026-58431 Public-only API token restriction is not enforced on team API routes | CVSS3: 4.3 | 0% Низкий | 22 дня назад | |
CVE-2026-5842 A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 0.3.75 is sufficient to resolve this issue. It is suggested to upgrade the affected component. | CVSS3: 7.3 | 0% Низкий | 5 месяцев назад | |
CVE-2026-58429 Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints | CVSS3: 4.9 | 0% Низкий | 22 дня назад | |
CVE-2026-58428 Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) | CVSS3: 6.5 | 0% Низкий | 22 дня назад | |
CVE-2026-58427 Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 | CVSS3: 7.5 | 0% Низкий | 22 дня назад | |
CVE-2026-58426 Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write | CVSS3: 9.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-58425 OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) | CVSS3: 4.3 | 0% Низкий | 22 дня назад | |
CVE-2026-58424 Permanent Fork PR Workflow Approval Gate Bypass | CVSS3: 8.9 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу