Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,627 advisories

Loading
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface High
CVE-2026-20779 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Kript0r3x Credited to Kript0r3x
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts High
CVE-2026-58422 was published for code.gitea.io/gitea (Go) Jul 21, 2026
chndlrx Credited to chndlrx
Gitea: Notification API leaks private issue metadata after access revocation High
CVE-2026-58419 was published for code.gitea.io/gitea (Go) Jul 21, 2026
ybsun0215 Credited to ybsun0215
Gitea: Unauthorized Access to Labels of Private Organizations High
CVE-2026-25038 was published for code.gitea.io/gitea (Go) Jul 21, 2026
ybsun0215 Credited to ybsun0215
Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write High
CVE-2026-27775 was published for code.gitea.io/gitea (Go) Jul 21, 2026
adrian-doyensec Credited to adrian-doyensec
Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private High
CVE-2026-24451 was published for code.gitea.io/gitea (Go) Jul 21, 2026
ybsun0215 Credited to ybsun0215
Gitea: Two SSRF findings High
CVE-2026-58314 was published for code.gitea.io/gitea (Go) Jul 21, 2026
xclow3n Credited to xclow3n
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests High
CVE-2026-58436 was published for code.gitea.io/gitea (Go) Jul 21, 2026
tonghuaroot Credited to tonghuaroot
Gitea: Repository Visibility Manipulation via Git Push Options High
CVE-2026-58437 was published for code.gitea.io/gitea (Go) Jul 21, 2026
prakhar0x01 Credited to prakhar0x01
khoadb175 Credited to khoadb175
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override High
CVE-2026-54481 was published for code.gitea.io/gitea (Go) Jul 21, 2026
sanil18 Credited to sanil18
Gitea: Permanent Fork PR Workflow Approval Gate Bypass High
CVE-2026-58424 was published for code.gitea.io/gitea (Go) Jul 21, 2026
prakhar0x01 Credited to prakhar0x01
Tomer-PL Credited to Tomer-PL
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service High
CVE-2026-58421 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects High
CVE-2026-28740 was published for gitea.dev (Go) Jul 21, 2026
m2hcz Credited to m2hcz
Gitea: Privilege Escalation via Access Token Scope Escalation in API High
CVE-2026-56654 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz and ohxorud-dev ohxorud-dev ohxorud-dev
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload High
CVE-2026-56755 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag High
CVE-2026-58439 was published for code.gitea.io/gitea (Go) Jul 21, 2026
yonatan-pl Credited to yonatan-pl
cyberlanc3r Credited to cyberlanc3r
File Browser: Colliding username normalization gives two users the same home directory High
CVE-2026-62685 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
je-lv Credited to je-lv and hacdias hacdias hacdias
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup High
CVE-2026-55667 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
babakizo420 Credited to babakizo420 and lexdotdev lexdotdev lexdotdev
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim High
CVE-2026-54560 was published for github.com/cloudreve/Cloudreve/v4 (Go) Jul 20, 2026
EaEa0001 Credited to EaEa0001
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies High
GHSA-8qqm-fp2q-v734 was published for github.com/zalando/skipper (Go) Jul 17, 2026
sec-reex Credited to sec-reex
Gitea has insufficient permission checks for Composer package source links High
CVE-2026-27771 was published for code.gitea.io/gitea (Go) Jul 17, 2026
DevNoScope Credited to DevNoScope
Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE High
CVE-2026-52833 was published for github.com/nuclio/nuclio (Go) Jul 16, 2026
j311yl0v3u Credited to j311yl0v3u and b0b0haha b0b0haha b0b0haha
ProTip! Advisories are also available from the GraphQL API