Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-56654HighGitea: Privilege Escalation via Access Token Scope Escalation in API
Gitea: Privilege Escalation via Access Token Scope Escalation in API
GHSA-rjvx-x5h2-6px5MediumGitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions
Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions
CVE-2026-58418Medium· 6.5Gitea: SSRF via HTTP Redirect in Repository Migration
Gitea: SSRF via HTTP Redirect in Repository Migration
CVE-2026-58421High· 7.5Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
CVE-2026-58423High· 7.7Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
CVE-2026-58424High· 8.9PoCGitea: Permanent Fork PR Workflow Approval Gate Bypass
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
CVE-2026-58426Critical· 9.6Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
CVE-2026-58438LowGitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
CVE-2026-58441Medium· 6.3Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
CVE-2026-58442Medium· 6.5Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass
CVE-2026-58444Medium· 4.3Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
CVE-2026-58445Low· 2.7Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
CVE-2026-42931Medium· 6.5Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
CVE-2026-58416Medium· 6.3Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
CVE-2026-50105Medium· 4.3Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
CVE-2026-58417MediumGitea: REST API exposes organization membership of private organizations to public
Gitea: REST API exposes organization membership of private organizations to public
CVE-2026-54481High· 7.5Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override
CVE-2026-58434LowGitea: Private Repository Metadata Remains Accessible After Access Revocation
Gitea: Private Repository Metadata Remains Accessible After Access Revocation
CVE-2026-55982MediumGitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
CVE-2026-59880HighImmutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
CVE-2026-13760High· 7.3aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling
aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling
CVE-2026-59892High· 7.5OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
CVE-2026-59890Medium· 6.1setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
CVE-2026-59884High· 7.5pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
CVE-2026-57894High· 8.5Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
CVE-2026-59891Critical· 9.6PoCCredential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
GHSA-p63j-vcc4-9vmvCritical· 9.4@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
GHSA-mhm7-754m-9p8wMedium· 6.5jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
GHSA-c2j3-45gr-mqc4LowDOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
GHSA-2p49-hgcm-8545High· 8.2SVGO removeScripts plugin leaves some executable scripts intact
SVGO removeScripts plugin leaves some executable scripts intact