git

package

Versions in this module

v1
Jun 29, 2026
Aug 29, 2026
Aug 13, 2026
Changes in this version
Jul 27, 2026
Jul 13, 2026
Changes in this version
Jun 29, 2026 GO-2026-6027 +41 more
Alert  GO-2026-6027: Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev
Alert  GO-2026-6028: Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev
Alert  GO-2026-6032: Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev
Alert  GO-2026-6033: Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev
Alert  GO-2026-6034: Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev
Alert  GO-2026-6035: Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev
Alert  GO-2026-6036: Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev
Alert  GO-2026-6037: Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev
Alert  GO-2026-6038: Gitea: Two SSRF findings in gitea.dev
Alert  GO-2026-6039: Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev
Alert  GO-2026-6040: Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev
Alert  GO-2026-6042: Gitea SSH Key Parser Denial of Service in gitea.dev
Alert  GO-2026-6045: Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev
Alert  GO-2026-6047: Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev
Alert  GO-2026-6048: Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev
Alert  GO-2026-6049: Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev
Alert  GO-2026-6050: Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev
Alert  GO-2026-6052: Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev
Alert  GO-2026-6053: Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev
Alert  GO-2026-6054: Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev
Alert  GO-2026-6055: Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev
Alert  GO-2026-6058: Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev
Alert  GO-2026-6059: Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev
Alert  GO-2026-6062: Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev
Alert  GO-2026-6063: Gitea: REST API exposes organization membership of private organizations to public in gitea.dev
Alert  GO-2026-6064: Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev
Alert  GO-2026-6065: Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev
Alert  GO-2026-6066: Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev
Alert  GO-2026-6067: Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev
Alert  GO-2026-6068: Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev
Alert  GO-2026-6069: Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev
Alert  GO-2026-6070: Gitea: draft release attachment disclosure via missing web authorization in gitea.dev
Alert  GO-2026-6071: Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev
Alert  GO-2026-6072: Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev
Alert  GO-2026-6073: Gitea LFS Deploy-Key Privilege Escalation in gitea.dev
Alert  GO-2026-6078: Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev
Alert  GO-2026-6079: Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev
Alert  GO-2026-6082: Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev
Alert  GO-2026-6083: Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev
Alert  GO-2026-6084: Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev
Alert  GO-2026-6085: Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev
Alert  GO-2026-6086: Gitea: Public-only repository tokens can update private PR head branches in gitea.dev

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL