Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,509 advisories

Loading
kamil-sawicki Credited to kamil-sawicki
Gitea: Permanent Fork PR Workflow Approval Gate Bypass High
CVE-2026-58424 was published for code.gitea.io/gitea (Go) Jul 21, 2026
prakhar0x01 Credited to prakhar0x01
Tomer-PL Credited to Tomer-PL
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service High
CVE-2026-58421 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Gitea: SSRF via HTTP Redirect in Repository Migration Moderate
CVE-2026-58418 was published for code.gitea.io/gitea (Go) Jul 21, 2026
moltenbit Credited to moltenbit
babakizo420 Credited to babakizo420
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects High
CVE-2026-28740 was published for gitea.dev (Go) Jul 21, 2026
m2hcz Credited to m2hcz
rz1027 Credited to rz1027
Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter Critical
CVE-2026-22874 was published for code.gitea.io/gitea (Go) Jul 21, 2026
JLLeitschuh Credited to JLLeitschuh and M8seven M8seven M8seven
Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions Moderate
GHSA-rjvx-x5h2-6px5 was published for code.gitea.io/gitea (Go) Jul 21, 2026
martijnperdaan52 Credited to martijnperdaan52
Gitea: Privilege Escalation via Access Token Scope Escalation in API High
CVE-2026-56654 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz and ohxorud-dev ohxorud-dev ohxorud-dev
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload High
CVE-2026-56755 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint Moderate
CVE-2026-58507 was published for code.gitea.io/gitea (Go) Jul 21, 2026
prakhar0x01 Credited to prakhar0x01
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content Moderate
CVE-2026-57886 was published for code.gitea.io/gitea (Go) Jul 21, 2026
zulloper Credited to zulloper
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim Low
CVE-2026-23603 was published for code.gitea.io/gitea (Go) Jul 21, 2026
alimezar Credited to alimezar, Vext-Labs, theluckystrike, prakhar0x01, AnuragBathani, and khoadb175 Vext-Labs Vext-Labs
theluckystrike theluckystrike prakhar0x01 prakhar0x01 AnuragBathani AnuragBathani khoadb175 khoadb175
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) Moderate
CVE-2026-58425 was published for code.gitea.io/gitea (Go) Jul 21, 2026
bl4cksku11 Credited to bl4cksku11
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads Moderate
CVE-2026-59763 was published for code.gitea.io/gitea (Go) Jul 21, 2026
kkkh1 Credited to kkkh1
Gitea Remember-Me Token Theft Not Invalidating Attacker Session Critical
CVE-2026-56750 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Gitea: draft release attachment disclosure via missing web authorization Moderate
CVE-2026-58432 was published for code.gitea.io/gitea (Go) Jul 21, 2026
z3r0s6 Credited to z3r0s6
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) Moderate
CVE-2026-58428 was published for code.gitea.io/gitea (Go) Jul 21, 2026
bl4cksku11 Credited to bl4cksku11
JebeenLee Credited to JebeenLee and alecclyde alecclyde alecclyde
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag High
CVE-2026-58439 was published for code.gitea.io/gitea (Go) Jul 21, 2026
yonatan-pl Credited to yonatan-pl
ProTip! Advisories are also available from the GraphQL API