Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-60004Critical· 9.8CISA KEV0dayPoCGitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
GO-2026-6074NoneGitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
CVE-2026-34966MediumGitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
CVE-2026-59765MediumGitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
CVE-2026-58429Medium· 4.9Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CVE-2026-55984Low· 2.7Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
CVE-2026-58435Medium· 5.4Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-55987High· 8.1Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
CVE-2026-58437High· 7.1Gitea: Repository Visibility Manipulation via Git Push Options
CVE-2026-56657MediumGitea SSH Key Parser Denial of Service
CVE-2026-58436HighGitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
CVE-2026-58314High· 7.7Gitea: Two SSRF findings
CVE-2026-58419High· 7.5Gitea: Notification API leaks private issue metadata after access revocation
CVE-2026-58422HighGitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
CVE-2026-58510Medium· 4.3Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
CVE-2026-57897Medium· 6.5Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
CVE-2026-58511Low· 2.7Gitea: Webhook Authorization Header Returned in Plaintext via API
CVE-2026-59766Medium· 4.3Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`
CVE-2026-58439High· 8.1Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
CVE-2026-56443Medium· 4.3Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
CVE-2026-58428Medium· 6.5Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
CVE-2026-58432Medium· 5.9Gitea: draft release attachment disclosure via missing web authorization
CVE-2026-56750CriticalGitea Remember-Me Token Theft Not Invalidating Attacker Session
CVE-2026-59763MediumGitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
CVE-2026-58425Medium· 4.3Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.