Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,475 advisories

Loading
rz1027 Credited to rz1027
Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter Critical
CVE-2026-22874 was published for code.gitea.io/gitea (Go) Jul 21, 2026
JLLeitschuh Credited to JLLeitschuh and M8seven M8seven M8seven
Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions Moderate
GHSA-rjvx-x5h2-6px5 was published for code.gitea.io/gitea (Go) Jul 21, 2026
martijnperdaan52 Credited to martijnperdaan52
Gitea: Privilege Escalation via Access Token Scope Escalation in API High
CVE-2026-56654 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz and ohxorud-dev ohxorud-dev ohxorud-dev
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload High
CVE-2026-56755 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint Moderate
CVE-2026-58507 was published for code.gitea.io/gitea (Go) Jul 21, 2026
prakhar0x01 Credited to prakhar0x01
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content Moderate
CVE-2026-57886 was published for code.gitea.io/gitea (Go) Jul 21, 2026
zulloper Credited to zulloper
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim Low
CVE-2026-23603 was published for code.gitea.io/gitea (Go) Jul 21, 2026
alimezar Credited to alimezar, Vext-Labs, theluckystrike, prakhar0x01, AnuragBathani, and khoadb175 Vext-Labs Vext-Labs
theluckystrike theluckystrike prakhar0x01 prakhar0x01 AnuragBathani AnuragBathani khoadb175 khoadb175
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) Moderate
CVE-2026-58425 was published for code.gitea.io/gitea (Go) Jul 21, 2026
bl4cksku11 Credited to bl4cksku11
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads Moderate
CVE-2026-59763 was published for code.gitea.io/gitea (Go) Jul 21, 2026
kkkh1 Credited to kkkh1
Gitea Remember-Me Token Theft Not Invalidating Attacker Session Critical
CVE-2026-56750 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Gitea: draft release attachment disclosure via missing web authorization Moderate
CVE-2026-58432 was published for code.gitea.io/gitea (Go) Jul 21, 2026
z3r0s6 Credited to z3r0s6
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) Moderate
CVE-2026-58428 was published for code.gitea.io/gitea (Go) Jul 21, 2026
bl4cksku11 Credited to bl4cksku11
JebeenLee Credited to JebeenLee and alecclyde alecclyde alecclyde
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag High
CVE-2026-58439 was published for code.gitea.io/gitea (Go) Jul 21, 2026
yonatan-pl Credited to yonatan-pl
cyberlanc3r Credited to cyberlanc3r
File Browser: Colliding username normalization gives two users the same home directory High
CVE-2026-62685 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
je-lv Credited to je-lv and hacdias hacdias hacdias
File Browser: Share API exposes the password hash and bypass token Low
CVE-2026-62684 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
je-lv Credited to je-lv and hacdias hacdias hacdias
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip) Moderate
CVE-2026-62843 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
je-lv Credited to je-lv and hacdias hacdias hacdias
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope Moderate
CVE-2026-55668 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
DavidCarliez Credited to DavidCarliez, riodrwn, and hacdias riodrwn riodrwn
hacdias hacdias
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup High
CVE-2026-55667 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
babakizo420 Credited to babakizo420, lexdotdev, and hacdias lexdotdev lexdotdev
hacdias hacdias
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses Moderate
CVE-2026-54562 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 20, 2026
baradika Credited to baradika and riodrwn riodrwn riodrwn
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim High
CVE-2026-54560 was published for github.com/cloudreve/Cloudreve/v4 (Go) Jul 20, 2026
EaEa0001 Credited to EaEa0001
ProTip! Advisories are also available from the GraphQL API