CVE-2026-56755
- EPSS 0.13%
- Veröffentlicht 13.08.2026 16:44:44
- Zuletzt bearbeitet 13.08.2026 19:17:25
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
CVE-2026-56657
- EPSS 0.17%
- Veröffentlicht 13.08.2026 16:44:43
- Zuletzt bearbeitet 13.08.2026 19:17:24
Gitea SSH Key Parser Denial of Service
CVE-2026-56750
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:43
- Zuletzt bearbeitet 14.08.2026 20:16:53
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
CVE-2026-55987
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:42
- Zuletzt bearbeitet 14.08.2026 20:16:53
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
CVE-2026-56443
- EPSS 0.17%
- Veröffentlicht 13.08.2026 16:44:42
- Zuletzt bearbeitet 14.08.2026 20:16:53
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
CVE-2026-56654
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:42
- Zuletzt bearbeitet 14.08.2026 20:16:53
Privilege Escalation via Access Token Scope Escalation in API
CVE-2026-55982
- EPSS 0.17%
- Veröffentlicht 13.08.2026 16:44:40
- Zuletzt bearbeitet 14.08.2026 18:18:13
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
CVE-2026-55984
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:40
- Zuletzt bearbeitet 14.08.2026 18:18:13
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
CVE-2026-50105
- EPSS 0.17%
- Veröffentlicht 13.08.2026 16:44:39
- Zuletzt bearbeitet 14.08.2026 21:17:18
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
CVE-2026-54481
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:39
- Zuletzt bearbeitet 14.08.2026 18:18:04
Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)