CVE-2026-58440
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:54
- Zuletzt bearbeitet 14.08.2026 20:16:54
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)
CVE-2026-58441
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:54
- Zuletzt bearbeitet 14.08.2026 20:16:54
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
CVE-2026-58438
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:53
- Zuletzt bearbeitet 14.08.2026 20:16:54
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
CVE-2026-58439
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:53
- Zuletzt bearbeitet 14.08.2026 20:16:54
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
CVE-2026-58436
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:52
- Zuletzt bearbeitet 14.08.2026 18:18:23
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
CVE-2026-58437
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:52
- Zuletzt bearbeitet 14.08.2026 19:17:20
Repository Visibility Manipulation via Git Push Options
CVE-2026-58434
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:51
- Zuletzt bearbeitet 14.08.2026 18:18:23
Private Repository Metadata Remains Accessible After Access Revocation
CVE-2026-58435
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:51
- Zuletzt bearbeitet 14.08.2026 18:18:23
Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-58432
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:50
- Zuletzt bearbeitet 14.08.2026 20:16:54
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
CVE-2026-58433
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:50
- Zuletzt bearbeitet 14.08.2026 20:16:54
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting