CVE-2026-58443
- EPSS 0.24%
- Veröffentlicht 13.08.2026 16:44:55
- Zuletzt bearbeitet 26.08.2026 16:53:48
Public-only repository tokens can update private PR head branches
CVE-2026-58440
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:54
- Zuletzt bearbeitet 26.08.2026 16:53:48
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)
CVE-2026-58441
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:54
- Zuletzt bearbeitet 26.08.2026 16:53:48
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
CVE-2026-58438
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:53
- Zuletzt bearbeitet 26.08.2026 16:53:48
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
CVE-2026-58439
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:53
- Zuletzt bearbeitet 26.08.2026 16:53:48
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
CVE-2026-58436
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:52
- Zuletzt bearbeitet 26.08.2026 16:53:48
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
CVE-2026-58437
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:52
- Zuletzt bearbeitet 26.08.2026 16:53:48
Repository Visibility Manipulation via Git Push Options
CVE-2026-58434
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:51
- Zuletzt bearbeitet 26.08.2026 16:53:48
Private Repository Metadata Remains Accessible After Access Revocation
CVE-2026-58435
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:51
- Zuletzt bearbeitet 26.08.2026 16:53:48
Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-58432
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:50
- Zuletzt bearbeitet 26.08.2026 16:53:48
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea