CVE-2026-58428
- EPSS 0.18%
- Veröffentlicht 13.08.2026 16:44:49
- Zuletzt bearbeitet 14.08.2026 18:18:23
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
CVE-2026-58429
- EPSS 0.17%
- Veröffentlicht 13.08.2026 16:44:49
- Zuletzt bearbeitet 14.08.2026 18:18:23
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CVE-2026-58431
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:49
- Zuletzt bearbeitet 14.08.2026 18:18:23
Public-only API token restriction is not enforced on team API routes
CVE-2026-58427
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:48
- Zuletzt bearbeitet 14.08.2026 18:18:23
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
CVE-2026-58417
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:47
- Zuletzt bearbeitet 14.08.2026 18:18:22
REST API exposes organization membership of private organizations to public
CVE-2026-58420
- EPSS 0.3%
- Veröffentlicht 13.08.2026 16:44:47
- Zuletzt bearbeitet 14.08.2026 18:18:22
Local File Inclusion via file:// URI in Migration Restore
CVE-2026-58425
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:47
- Zuletzt bearbeitet 14.08.2026 18:18:23
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
CVE-2026-58416
- EPSS 0.25%
- Veröffentlicht 13.08.2026 16:44:46
- Zuletzt bearbeitet 13.08.2026 19:17:26
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
CVE-2026-57894
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:45
- Zuletzt bearbeitet 14.08.2026 18:18:19
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
CVE-2026-57897
- EPSS 0.3%
- Veröffentlicht 13.08.2026 16:44:45
- Zuletzt bearbeitet 13.08.2026 19:17:26
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs