CVE-2026-24059
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:48:52
- Zuletzt bearbeitet 14.08.2026 18:17:24
The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET req...
CVE-2026-24791
- EPSS 0.25%
- Veröffentlicht 13.08.2026 16:48:52
- Zuletzt bearbeitet 13.08.2026 19:17:19
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
CVE-2026-59765
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:59
- Zuletzt bearbeitet 14.08.2026 19:17:23
SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
CVE-2026-58510
- EPSS 0.19%
- Veröffentlicht 13.08.2026 16:44:58
- Zuletzt bearbeitet 13.08.2026 20:17:23
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
CVE-2026-59763
- EPSS 0.24%
- Veröffentlicht 13.08.2026 16:44:58
- Zuletzt bearbeitet 13.08.2026 19:17:29
Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
CVE-2026-58507
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:57
- Zuletzt bearbeitet 14.08.2026 19:17:20
Private Repository Existence Disclosure via go-get Meta Endpoint
CVE-2026-58508
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:57
- Zuletzt bearbeitet 14.08.2026 19:17:21
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
CVE-2026-58444
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:56
- Zuletzt bearbeitet 14.08.2026 19:17:20
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
CVE-2026-58445
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:56
- Zuletzt bearbeitet 14.08.2026 19:17:20
Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
CVE-2026-58443
- EPSS 0.24%
- Veröffentlicht 13.08.2026 16:44:55
- Zuletzt bearbeitet 14.08.2026 20:16:55
Public-only repository tokens can update private PR head branches