Количество 389 227
Количество 389 227
CVE-2026-58433
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
CVE-2026-58432
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
CVE-2026-58431
Public-only API token restriction is not enforced on team API routes
CVE-2026-5842
A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 0.3.75 is sufficient to resolve this issue. It is suggested to upgrade the affected component.
CVE-2026-58429
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CVE-2026-58428
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
CVE-2026-58427
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
CVE-2026-58426
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
CVE-2026-58425
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
CVE-2026-58424
Permanent Fork PR Workflow Approval Gate Bypass
CVE-2026-58423
LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
CVE-2026-58422
Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
CVE-2026-58421
Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
CVE-2026-58420
Local File Inclusion via file:// URI in Migration Restore
CVE-2026-5841
A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2026-58419
Notification API leaks private issue metadata after access revocation
CVE-2026-58418
SSRF via HTTP Redirect in Repository Migration
CVE-2026-58417
REST API exposes organization membership of private organizations to public
CVE-2026-58416
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
CVE-2026-58414
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using `_collectBackupFiles()`. `_collectBackupFiles()` uses `statSync(full)`, which follows symlinks. If `data/<env>` contains a symlink to a directory outside the environment root, backup recursion follows the symlink and copies external files into `data/<env>/.backups/<backupId>/`. An attacker who can place a symlink under the environment data directory can cause backup operations to disclose files outside the environment root into backup artifacts. The issue is fixed in v5.12.2. `_collectBackupFiles()` now uses `lstatSync` instead of `statSync` and skips any entry where `isSymbolicLink()` is true. Symlinks are never traversed, so `backup()` can no longer follow a link out of the environment root and copy external files into a backup artifact.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-58433 Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting | CVSS3: 9.1 | 0% Низкий | 27 дней назад | |
CVE-2026-58432 Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea | CVSS3: 5.9 | 0% Низкий | 27 дней назад | |
CVE-2026-58431 Public-only API token restriction is not enforced on team API routes | CVSS3: 4.3 | 0% Низкий | 27 дней назад | |
CVE-2026-5842 A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 0.3.75 is sufficient to resolve this issue. It is suggested to upgrade the affected component. | CVSS3: 7.3 | 0% Низкий | 5 месяцев назад | |
CVE-2026-58429 Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints | CVSS3: 4.9 | 0% Низкий | 27 дней назад | |
CVE-2026-58428 Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) | CVSS3: 6.5 | 0% Низкий | 27 дней назад | |
CVE-2026-58427 Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 | CVSS3: 7.5 | 0% Низкий | 27 дней назад | |
CVE-2026-58426 Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write | CVSS3: 9.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-58425 OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) | CVSS3: 4.3 | 0% Низкий | 27 дней назад | |
CVE-2026-58424 Permanent Fork PR Workflow Approval Gate Bypass | CVSS3: 8.9 | 0% Низкий | 2 месяца назад | |
CVE-2026-58423 LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories | CVSS3: 7.7 | 1% Низкий | 2 месяца назад | |
CVE-2026-58422 Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts | CVSS3: 9.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-58421 Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-58420 Local File Inclusion via file:// URI in Migration Restore | CVSS3: 4.4 | 0% Низкий | 27 дней назад | |
CVE-2026-5841 A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. | CVSS3: 7.3 | 1% Низкий | 5 месяцев назад | |
CVE-2026-58419 Notification API leaks private issue metadata after access revocation | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-58418 SSRF via HTTP Redirect in Repository Migration | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-58417 REST API exposes organization membership of private organizations to public | CVSS3: 7.5 | 0% Низкий | 27 дней назад | |
CVE-2026-58416 Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) | CVSS3: 7.1 | 0% Низкий | 27 дней назад | |
CVE-2026-58414 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using `_collectBackupFiles()`. `_collectBackupFiles()` uses `statSync(full)`, which follows symlinks. If `data/<env>` contains a symlink to a directory outside the environment root, backup recursion follows the symlink and copies external files into `data/<env>/.backups/<backupId>/`. An attacker who can place a symlink under the environment data directory can cause backup operations to disclose files outside the environment root into backup artifacts. The issue is fixed in v5.12.2. `_collectBackupFiles()` now uses `lstatSync` instead of `statSync` and skips any entry where `isSymbolicLink()` is true. Symlinks are never traversed, so `backup()` can no longer follow a link out of the environment root and copy external files into a backup artifact. | CVSS3: 5.5 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу