VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-56654High
2mo ago

Gitea: Privilege Escalation via Access Token Scope Escalation in API

Gitea: Privilege Escalation via Access Token Scope Escalation in API

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.60%via GHSA
GHSA-rjvx-x5h2-6px5Medium
2mo ago

Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions

Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions

▾ Sunlitgitea · code.gitea.io/giteavia GHSA
CVE-2026-58418Medium· 6.5
2mo ago

Gitea: SSRF via HTTP Redirect in Repository Migration

Gitea: SSRF via HTTP Redirect in Repository Migration

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.41%via GHSA
CVE-2026-58421High· 7.5
2mo ago

Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.58%via GHSA
CVE-2026-58423High· 7.7
2mo ago

Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.54%via GHSA
CVE-2026-58424High· 8.9PoC
2mo ago

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

▾ Midnightgitea · code.gitea.io/giteaEPSS 0.37%via GHSA
CVE-2026-58426Critical· 9.6
2mo ago

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

▾ Midnightgitea · code.gitea.io/giteaEPSS 0.30%via GHSA
CVE-2026-58438Low
2mo ago

Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access

Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access

▾ Sunlitgitea.dev · gitea.devEPSS 0.47%via GHSA
CVE-2026-58441Medium· 6.3
2mo ago

Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL

Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.17%via GHSA
CVE-2026-58442Medium· 6.5
2mo ago

Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass

Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.43%via GHSA
CVE-2026-58444Medium· 4.3
2mo ago

Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.36%via GHSA
CVE-2026-58445Low· 2.7
2mo ago

Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.37%via GHSA
CVE-2026-42931Medium· 6.5
2mo ago

Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.53%via GHSA
CVE-2026-58416Medium· 6.3
2mo ago

Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

▾ Sunlitgitea.dev · gitea.devEPSS 0.31%via GHSA
CVE-2026-50105Medium· 4.3
2mo ago

Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.36%via GHSA
CVE-2026-58417Medium
2mo ago

Gitea: REST API exposes organization membership of private organizations to public

Gitea: REST API exposes organization membership of private organizations to public

▾ Sunlitgitea.dev · gitea.devEPSS 0.47%via GHSA
CVE-2026-54481High· 7.5
2mo ago

Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override

Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.30%via GHSA
CVE-2026-58434Low
2mo ago

Gitea: Private Repository Metadata Remains Accessible After Access Revocation

Gitea: Private Repository Metadata Remains Accessible After Access Revocation

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.47%via GHSA
CVE-2026-55982Medium
2mo ago

Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.51%via GHSA
CVE-2026-59880High
2mo ago

Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set

Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set

▾ Twilightimmutable · immutableEPSS 0.66%via GHSA
CVE-2026-13760High· 7.3
2mo ago

aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling

aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling

▾ Twilightaws-cdk-lib · aws-cdk-libEPSS 1.2%via GHSA
CVE-2026-59892High· 7.5
2mo ago

OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header

OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header

▾ Twilightopentelemetry · @opentelemetry/propagator-jaegerEPSS 0.78%via GHSA
CVE-2026-59890Medium· 6.1
2mo ago

setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+

setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+

▾ Sunlitsetuptools · setuptoolsEPSS 0.40%via OSV
CVE-2026-59884High· 7.5
2mo ago

pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs

pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs

▾ Twilightpyasn1 · pyasn1EPSS 0.62%via OSV
CVE-2026-57894High· 8.5
2mo ago

Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.36%via GHSA
CVE-2026-59891Critical· 9.6PoC
2mo ago

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

▾ Abyssalsigstore · @sigstore/ociEPSS 0.47%via GHSA
GHSA-p63j-vcc4-9vmvCritical· 9.4
2mo ago

@vitest/browser: Browser Mode provider commands bypass the file-access permission gate

@vitest/browser: Browser Mode provider commands bypass the file-access permission gate

▾ Midnightvitest · @vitest/browservia GHSA
GHSA-mhm7-754m-9p8wMedium· 6.5
2mo ago

jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`

jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`

▾ Sunlitfasterxml · com.fasterxml.jackson.core:jackson-databindvia GHSA
GHSA-c2j3-45gr-mqc4Low
2mo ago

DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.

DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.

▾ Sunlitdompurify · dompurifyvia GHSA
GHSA-2p49-hgcm-8545High· 8.2
2mo ago

SVGO removeScripts plugin leaves some executable scripts intact

SVGO removeScripts plugin leaves some executable scripts intact

▾ Twilightsvgo · svgovia GHSA
CVEs tagged “ghsa” — page 73 · VulnSea