CVE-2026-58433
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:50
- Zuletzt bearbeitet 26.08.2026 16:53:48
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
CVE-2026-58428
- EPSS 0.18%
- Veröffentlicht 13.08.2026 16:44:49
- Zuletzt bearbeitet 26.08.2026 16:53:48
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
CVE-2026-58429
- EPSS 0.17%
- Veröffentlicht 13.08.2026 16:44:49
- Zuletzt bearbeitet 26.08.2026 16:53:48
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CVE-2026-58431
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:49
- Zuletzt bearbeitet 26.08.2026 16:53:48
Public-only API token restriction is not enforced on team API routes
CVE-2026-58427
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:48
- Zuletzt bearbeitet 26.08.2026 16:53:48
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
CVE-2026-58417
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:47
- Zuletzt bearbeitet 26.08.2026 16:53:48
REST API exposes organization membership of private organizations to public
CVE-2026-58420
- EPSS 0.3%
- Veröffentlicht 13.08.2026 16:44:47
- Zuletzt bearbeitet 26.08.2026 16:53:48
Local File Inclusion via file:// URI in Migration Restore
CVE-2026-58425
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:47
- Zuletzt bearbeitet 26.08.2026 16:53:48
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
CVE-2026-58416
- EPSS 0.25%
- Veröffentlicht 13.08.2026 16:44:46
- Zuletzt bearbeitet 26.08.2026 16:53:48
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
CVE-2026-57894
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:45
- Zuletzt bearbeitet 26.08.2026 16:53:48
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration