VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

GHSA-f88m-g3jw-g9cjHigh
2mo ago

sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591

sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591

▾ Twilightsharp · sharpvia GHSA
CVE-2026-55984Low· 2.7
2mo ago

Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.46%via GHSA
CVE-2026-58420Medium
2mo ago

Gitea: Local File Inclusion via file:// URI in Migration Restore

Gitea: Local File Inclusion via file:// URI in Migration Restore

▾ Sunlitgitea.dev · gitea.devEPSS 0.47%via GHSA
CVE-2026-58435Medium· 5.4
2mo ago

Gitea LFS Deploy-Key Privilege Escalation

Gitea LFS Deploy-Key Privilege Escalation

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.29%via GHSA
CVE-2026-55987High· 8.1
2mo ago

Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)

Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.41%via GHSA
CVE-2026-58437High· 7.1
2mo ago

Gitea: Repository Visibility Manipulation via Git Push Options

Gitea: Repository Visibility Manipulation via Git Push Options

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.34%via GHSA
CVE-2026-56657Medium· 6.2
2mo ago

Gitea SSH Key Parser Denial of Service

Gitea SSH Key Parser Denial of Service

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.17%via OSV
CVE-2026-58436High
2mo ago

Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.61%via GHSA
CVE-2026-58314High· 7.7
2mo ago

Gitea: Two SSRF findings

Gitea: Two SSRF findings

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.40%via OSV
CVE-2026-58419High· 7.5
2mo ago

Gitea: Notification API leaks private issue metadata after access revocation

Gitea: Notification API leaks private issue metadata after access revocation

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.51%via GHSA
CVE-2026-58422High
2mo ago

Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.62%via GHSA
CVE-2026-58427Medium
2mo ago

Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

▾ Sunlitgitea.dev · gitea.devEPSS 0.47%via GHSA
CVE-2026-58431Medium· 4.3
2mo ago

Gitea: Public-only API token restriction is not enforced on team API routes

Gitea: Public-only API token restriction is not enforced on team API routes

▾ Sunlitgitea.dev · gitea.devEPSS 0.33%via GHSA
CVE-2026-58510Medium· 4.3
2mo ago

Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.33%via GHSA
CVE-2026-57897Medium· 6.5
2mo ago

Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.41%via GHSA
CVE-2026-58511Low· 2.7
2mo ago

Gitea: Webhook Authorization Header Returned in Plaintext via API

Gitea: Webhook Authorization Header Returned in Plaintext via API

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.39%via GHSA
GHSA-956x-8gvw-wg5vHigh· 8.4
2mo ago

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

▾ TwilightGitPython · GitPythonvia GHSA
CVE-2026-58440Medium· 6.8
2mo ago

Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content

Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content

▾ Sunlitgitea.dev · gitea.devEPSS 0.48%via GHSA
CVE-2026-59766Medium· 4.3
2mo ago

Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`

Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`

▾ Sunlitgitea · code.gitea.io/giteavia GHSA
CVE-2026-58439High· 8.1
2mo ago

Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.53%via GHSA
CVE-2026-56443Medium· 4.3
2mo ago

Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / …

Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.53%via OSV
CVE-2026-58428Medium· 6.5
2mo ago

Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.46%via GHSA
CVE-2026-58432Medium· 5.9
2mo ago

Gitea: draft release attachment disclosure via missing web authorization

Gitea: draft release attachment disclosure via missing web authorization

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.43%via GHSA
CVE-2026-56750Critical
2mo ago

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

▾ Midnightgitea · code.gitea.io/giteaEPSS 0.48%via GHSA
CVE-2026-59763Medium
2mo ago

Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.41%via GHSA
CVE-2026-58425Medium· 4.3
2mo ago

Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.33%via GHSA
CVE-2026-23603Low· 3.1
2mo ago

Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.29%via GHSA
CVE-2026-57886Medium· 5.9
2mo ago

Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content

Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.31%via GHSA
CVE-2026-58507Medium· 5.3
2mo ago

Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint

Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.38%via GHSA
CVE-2026-56755High
2mo ago

Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload

Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.17%via GHSA
CVEs tagged “ghsa” — page 72 · VulnSea