GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,368
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,124
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
33,519 advisories
Filter by severity
Gitea: SSRF via HTTP Redirect in Repository Migration
Moderate
CVE-2026-58418
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data
Moderate
CVE-2026-27761
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
High
CVE-2026-28740
was published
for
gitea.dev
(Go)
Jul 21, 2026
Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`
Critical
CVE-2026-20896
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter
Critical
CVE-2026-22874
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions
Moderate
GHSA-rjvx-x5h2-6px5
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API
High
CVE-2026-56654
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
High
CVE-2026-56755
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint
Moderate
CVE-2026-58507
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
Moderate
CVE-2026-57886
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
Low
CVE-2026-23603
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
Moderate
CVE-2026-58425
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
Moderate
CVE-2026-59763
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
Critical
CVE-2026-56750
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: draft release attachment disclosure via missing web authorization
Moderate
CVE-2026-58432
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
Moderate
CVE-2026-58428
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
Moderate
CVE-2026-56443
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
High
CVE-2026-58439
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`
Moderate
CVE-2026-59766
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content
Moderate
CVE-2026-58440
was published
for
gitea.dev
(Go)
Jul 21, 2026
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
High
GHSA-956x-8gvw-wg5v
was published
for
GitPython
(pip)
Jul 21, 2026
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
High
GHSA-2f96-g7mh-g2hx
was published
for
GitPython
(pip)
Jul 21, 2026
GitPython unsafe clone option gate bypass through joined short options
High
GHSA-v396-v7q4-x2qj
was published
for
GitPython
(pip)
Jul 21, 2026
SVGO removeScripts plugin leaves some executable scripts intact
High
GHSA-2p49-hgcm-8545
was published
for
svgo
(npm)
Jul 21, 2026
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
Low
GHSA-c2j3-45gr-mqc4
was published
for
dompurify
(npm)
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API