VulnSea

Tagged “go”

CVEs tagged go, newest first.

1735 CVEsRSS

CVE-2026-59763Medium
2mo ago

Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.41%via GHSA
CVE-2026-58425Medium· 4.3
2mo ago

Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.33%via GHSA
CVE-2026-23603Low· 3.1
2mo ago

Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.29%via GHSA
CVE-2026-57886Medium· 5.9
2mo ago

Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content

Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.31%via GHSA
CVE-2026-58507Medium· 5.3
2mo ago

Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint

Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.38%via GHSA
CVE-2026-56755High
2mo ago

Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload

Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.17%via GHSA
CVE-2026-56654High
2mo ago

Gitea: Privilege Escalation via Access Token Scope Escalation in API

Gitea: Privilege Escalation via Access Token Scope Escalation in API

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.60%via GHSA
GHSA-rjvx-x5h2-6px5Medium
2mo ago

Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions

Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions

▾ Sunlitgitea · code.gitea.io/giteavia GHSA
CVE-2026-58418Medium· 6.5
2mo ago

Gitea: SSRF via HTTP Redirect in Repository Migration

Gitea: SSRF via HTTP Redirect in Repository Migration

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.41%via GHSA
CVE-2026-58421High· 7.5
2mo ago

Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.58%via GHSA
CVE-2026-58423High· 7.7
2mo ago

Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.54%via GHSA
CVE-2026-58424High· 8.9PoC
2mo ago

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

▾ Midnightgitea · code.gitea.io/giteaEPSS 0.37%via GHSA
CVE-2026-58426Critical· 9.6
2mo ago

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

▾ Midnightgitea · code.gitea.io/giteaEPSS 0.30%via GHSA
CVE-2026-58438Low
2mo ago

Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access

Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access

▾ Sunlitgitea.dev · gitea.devEPSS 0.47%via GHSA
CVE-2026-58441Medium· 6.3
2mo ago

Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL

Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.17%via GHSA
CVE-2026-58442Medium· 6.5
2mo ago

Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass

Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.43%via GHSA
CVE-2026-58444Medium· 4.3
2mo ago

Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.36%via GHSA
CVE-2026-58445Low· 2.7
2mo ago

Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.37%via GHSA
CVE-2026-42931Medium· 6.5
2mo ago

Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.53%via GHSA
CVE-2026-58416Medium· 6.3
2mo ago

Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

▾ Sunlitgitea.dev · gitea.devEPSS 0.31%via GHSA
CVE-2026-50105Medium· 4.3
2mo ago

Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.36%via GHSA
CVE-2026-58417Medium
2mo ago

Gitea: REST API exposes organization membership of private organizations to public

Gitea: REST API exposes organization membership of private organizations to public

▾ Sunlitgitea.dev · gitea.devEPSS 0.47%via GHSA
CVE-2026-54481High· 7.5
2mo ago

Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override

Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.30%via GHSA
CVE-2026-58434Low
2mo ago

Gitea: Private Repository Metadata Remains Accessible After Access Revocation

Gitea: Private Repository Metadata Remains Accessible After Access Revocation

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.47%via GHSA
CVE-2026-55982Medium
2mo ago

Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.51%via GHSA
CVE-2026-57894High· 8.5
2mo ago

Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.36%via GHSA
CVE-2026-62843Medium· 6.8
2mo ago

File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)

File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.39%via GHSA
CVE-2026-62685High· 8.1
2mo ago

File Browser: Colliding username normalization gives two users the same home directory

File Browser: Colliding username normalization gives two users the same home directory

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.55%via GHSA
CVE-2026-54560High· 7.6
2mo ago

Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim

Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim

▾ Twilightcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.46%via GHSA
CVE-2026-54562Medium· 6.5
2mo ago

Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses

Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.40%via GHSA
CVEs tagged “go” — page 20 · VulnSea