Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-58423 |
|
Authentication Bypass in code.gitea.io/gitea (CVE-2026-58423)
authentication bypass in code.gitea.io/gitea (CVE-2026-58423). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-58422 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-58422)
vulnerability in code.gitea.io/gitea (CVE-2026-58422). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v1/admin/users/alice`. Mitigation: upgrade to `1.26.4` or later.
|
| CVE-2026-58421 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-58421)
vulnerability in code.gitea.io/gitea (CVE-2026-58421). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/repos/{owner}/{repo}/pulls`. Mitigation: upgrade to `1.26.4` or later.
|
| CVE-2026-58419 |
|
Information Disclosure in code.gitea.io/gitea (CVE-2026-58419)
vulnerability in code.gitea.io/gitea (CVE-2026-58419). Confidential information can be exposed externally. Exploitable via `GET /api/v1/repos/sun/{repo}/issues/1`. Mitigation: upgrade to `1.25.4` or later.
|
| CVE-2026-58418 |
|
SSRF (Server-Side Request Forgery) in code.gitea.io/gitea (CVE-2026-58418)
SSRF in code.gitea.io/gitea (CVE-2026-58418). Confidential information can be exposed externally. Exploitable via `POST /api/v1/repos/migrate`. Mitigation: upgrade to `1.26.4` or later.
|
| CVE-2026-28740 |
|
Vulnerability in gitea.dev (CVE-2026-28740)
vulnerability in gitea.dev (CVE-2026-28740). Confidential information can be exposed externally. Exploitable via ``unit.TypeInvalid``. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-27775 |
|
Authorization Flaw in code.gitea.io/gitea (CVE-2026-27775)
vulnerability in code.gitea.io/gitea (CVE-2026-27775). Successful exploitation can lead to full system takeover. Exploitable via `POST /{owner}/{repo}.git/git-receive-pack`. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-27771 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-27771)
vulnerability in code.gitea.io/gitea (CVE-2026-27771). Confidential information can be exposed externally. Mitigation: upgrade to `1.26.2` or later.
|
| CVE-2026-27761 |
|
Authorization Flaw in code.gitea.io/gitea (CVE-2026-27761)
vulnerability in code.gitea.io/gitea (CVE-2026-27761). Risk of unauthorized operations or information disclosure. Exploitable via ``webAuth.AllowBasic``. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-25038 |
|
Information Disclosure in code.gitea.io/gitea (CVE-2026-25038)
vulnerability in code.gitea.io/gitea (CVE-2026-25038). Confidential information can be exposed externally. Exploitable via `GET /api/v1/orgs/{org}/labels`. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-24451 |
|
Information Disclosure in code.gitea.io/gitea (CVE-2026-24451)
vulnerability in code.gitea.io/gitea (CVE-2026-24451). Confidential information can be exposed externally. Exploitable via `POST /api/v1/repos/{owner}/{repo}/merge-upstream`. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-22874 |
|
SSRF (Server-Side Request Forgery) in code.gitea.io/gitea (CVE-2026-22874)
SSRF in code.gitea.io/gitea (CVE-2026-22874). Confidential information can be exposed externally. Exploitable via ``MatchBuiltinExternal``. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-20896 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-20896)
vulnerability in code.gitea.io/gitea (CVE-2026-20896). Successful exploitation can lead to full system takeover. Exploitable via ``app.ini``. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-20779 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-20779)
vulnerability in code.gitea.io/gitea (CVE-2026-20779). Confidential information can be exposed externally. Exploitable via `POST /user/two_factor`. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-14355 |
|
Vulnerability in php (CVE-2026-14355)
vulnerability in php (CVE-2026-14355). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.2.32, 8.3.32, 8.4.23, 8.5.8` or later.
|
| UBUNTU-CVE-2026-12481 |
|
Vulnerability in keras (UBUNTU-CVE-2026-12481)
vulnerability in keras (UBUNTU-CVE-2026-12481). Successful exploitation can lead to full system takeover. Exploitable via ``Lambda``.
|
| UBUNTU-CVE-2026-14610 |
|
Vulnerability in assimp (UBUNTU-CVE-2026-14610)
vulnerability in assimp (UBUNTU-CVE-2026-14610). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14608 |
|
Vulnerability in CVE-2026-14608 (CVE-2026-14608)
vulnerability in CVE-2026-14608 (CVE-2026-14608). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14607 |
|
Buffer Overflow in c (CVE-2026-14607)
vulnerability in c (CVE-2026-14607). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14606 |
|
Buffer Overflow in CVE-2026-14606 (CVE-2026-14606)
vulnerability in CVE-2026-14606 (CVE-2026-14606). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14605 |
|
Buffer Overflow in CVE-2026-14605 (CVE-2026-14605)
vulnerability in CVE-2026-14605 (CVE-2026-14605). Successful exploitation can lead to full system takeover.
|
| GHSA-86fh-6m37-f9v4 |
|
Vulnerability in debugcli (GHSA-86fh-6m37-f9v4)
vulnerability in debugcli (GHSA-86fh-6m37-f9v4). Risk of unauthorized operations or information disclosure. Exploitable via ``debugcli``.
|
| SUSE-SU-2026:2758-1 |
|
Vulnerability in python-pip (SUSE-SU-2026:2758-1)
vulnerability in python-pip (SUSE-SU-2026:2758-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.0.1-13.20.1` or later.
|
| SUSE-SU-2026:2757-1 |
|
Vulnerability in openCryptoki (SUSE-SU-2026:2757-1)
vulnerability in openCryptoki (SUSE-SU-2026:2757-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.26.0-150700.5.17.1` or later.
|
| SUSE-SU-2026:2756-1 |
|
Vulnerability in gimp (SUSE-SU-2026:2756-1)
vulnerability in gimp (SUSE-SU-2026:2756-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.10.30-150400.3.53.1` or later.
|
| SUSE-SU-2026:2755-1 |
|
Vulnerability in xdg-dbus-proxy (SUSE-SU-2026:2755-1)
vulnerability in xdg-dbus-proxy (SUSE-SU-2026:2755-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.1.5-150600.3.5.1` or later.
|
| MINI-2gh6-2mr3-m2cc |
|
MINI-2gh6-2mr3-m2cc |
| MINI-j9p2-j5qq-wx4j |
|
MINI-j9p2-j5qq-wx4j |
| MINI-rg25-fgr9-2j37 |
|
MINI-rg25-fgr9-2j37 |
| MINI-w6g7-x33q-q54c |
|
MINI-w6g7-x33q-q54c |
| MINI-w7q4-h6h7-wgcq |
|
MINI-w7q4-h6h7-wgcq |
| MINI-mv3x-8qw7-8x7h |
|
MINI-mv3x-8qw7-8x7h |
| MINI-g98f-hr6w-mr96 |
|
MINI-g98f-hr6w-mr96 |
| MINI-jrqf-w99c-859p |
|
MINI-jrqf-w99c-859p |
| MINI-vjfg-rv97-m55g |
|
MINI-vjfg-rv97-m55g |
| MINI-7c59-4pmj-gm2v |
|
MINI-7c59-4pmj-gm2v |
| MINI-54c5-jxj9-xrj4 |
|
MINI-54c5-jxj9-xrj4 |
| MINI-f9x7-m6jw-2jj9 |
|
MINI-f9x7-m6jw-2jj9 |
| MINI-9xhj-3577-jj5c |
|
MINI-9xhj-3577-jj5c |
| MINI-2hqx-95c9-5466 |
|
MINI-2hqx-95c9-5466 |
| MINI-jp7v-pmv2-p4h4 |
|
MINI-jp7v-pmv2-p4h4 |
| MINI-j9qh-22qj-7xw6 |
|
MINI-j9qh-22qj-7xw6 |
| MINI-jwp3-98g2-53j5 |
|
MINI-jwp3-98g2-53j5 |
| MINI-hp3x-q339-wc9r |
|
MINI-hp3x-q339-wc9r |
| MINI-8jv5-6wpr-x3q4 |
|
MINI-8jv5-6wpr-x3q4 |
| MINI-rx8r-rp5x-cg9r |
|
MINI-rx8r-rp5x-cg9r |
| MINI-hcx6-6r22-84hw |
|
MINI-hcx6-6r22-84hw |
| MINI-gfh5-m27h-6hxh |
|
MINI-gfh5-m27h-6hxh |
| MINI-fwcg-mjpv-pqj2 |
|
MINI-fwcg-mjpv-pqj2 |
| MINI-966v-w737-j2j6 |
|
MINI-966v-w737-j2j6 |