Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
GHSA-f88m-g3jw-g9cjHighsharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
CVE-2026-55984Low· 2.7Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
CVE-2026-58420MediumGitea: Local File Inclusion via file:// URI in Migration Restore
Gitea: Local File Inclusion via file:// URI in Migration Restore
CVE-2026-58435Medium· 5.4Gitea LFS Deploy-Key Privilege Escalation
Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-55987High· 8.1Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
CVE-2026-58437High· 7.1Gitea: Repository Visibility Manipulation via Git Push Options
Gitea: Repository Visibility Manipulation via Git Push Options
CVE-2026-56657Medium· 6.2Gitea SSH Key Parser Denial of Service
Gitea SSH Key Parser Denial of Service
CVE-2026-58436HighGitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
CVE-2026-58314High· 7.7Gitea: Two SSRF findings
Gitea: Two SSRF findings
CVE-2026-58419High· 7.5Gitea: Notification API leaks private issue metadata after access revocation
Gitea: Notification API leaks private issue metadata after access revocation
CVE-2026-58422HighGitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
CVE-2026-58427MediumGitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
CVE-2026-58431Medium· 4.3Gitea: Public-only API token restriction is not enforced on team API routes
Gitea: Public-only API token restriction is not enforced on team API routes
CVE-2026-58510Medium· 4.3Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
CVE-2026-57897Medium· 6.5Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
CVE-2026-58511Low· 2.7Gitea: Webhook Authorization Header Returned in Plaintext via API
Gitea: Webhook Authorization Header Returned in Plaintext via API
GHSA-956x-8gvw-wg5vHigh· 8.4GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
CVE-2026-58440Medium· 6.8Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content
CVE-2026-59766Medium· 4.3Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`
CVE-2026-58439High· 8.1Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
CVE-2026-56443Medium· 4.3Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / …
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
CVE-2026-58428Medium· 6.5Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
CVE-2026-58432Medium· 5.9Gitea: draft release attachment disclosure via missing web authorization
Gitea: draft release attachment disclosure via missing web authorization
CVE-2026-56750CriticalGitea Remember-Me Token Theft Not Invalidating Attacker Session
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
CVE-2026-59763MediumGitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
CVE-2026-58425Medium· 4.3Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
CVE-2026-23603Low· 3.1Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
CVE-2026-57886Medium· 5.9Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
CVE-2026-58507Medium· 5.3Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint
CVE-2026-56755HighGitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload