| CVE-2026-58420 | Local File Inclusion via file:// URI in Migration Restore | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:47 | Deep Dive |
| CVE-2026-57897 | Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:46 | Deep Dive |
| CVE-2026-58314 | Two SSRF findings in Gitea 1.26.2 | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:46 | Deep Dive |
| CVE-2026-57886 | Cross-repository issue/comment attachment re-linking can expose private attachment content | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:45 | Deep Dive |
| CVE-2026-57894 | Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:45 | Deep Dive |
| CVE-2026-56750 | Gitea Remember-Me Token Theft Not Invalidating Attacker Session | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:44 | Deep Dive |
| CVE-2026-56755 | Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:44 | Deep Dive |
| CVE-2026-56654 | Privilege Escalation via Access Token Scope Escalation in API | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:43 | Deep Dive |
| CVE-2026-56657 | Gitea SSH Key Parser Denial of Service | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:43 | Deep Dive |
| CVE-2026-55987 | OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:42 | Deep Dive |
| CVE-2026-56443 | Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:42 | Deep Dive |
| CVE-2026-55986 | Email Management API Bypasses ManageCredentials Feature Restrictions | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:42 | Deep Dive |
| CVE-2026-55984 | Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:41 | Deep Dive |
| CVE-2026-54481 | Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295) | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:40 | Deep Dive |
| CVE-2026-55982 | OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:40 | Deep Dive |
| CVE-2026-42931 | Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:39 | Deep Dive |
| CVE-2026-50105 | RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:39 | Deep Dive |
| CVE-2026-23603 | Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim | Gitea | Gitea Open Source Git Server | - | - | 2026-08-13 16:44:38 | Deep Dive |
| CVE-2026-59109 | Zalktis: SQL injection via partner-controlled fields in imported e-invoices | Zalktis Programmas (SIA "Zalktis Programmas") | Zalktis | High | 8.8 | 2026-08-13 16:40:02 | Deep Dive |
| CVE-2026-73266 | Clusterclaims-controller: clusterclaims-controller: tenant-controlled clusterclaim labels propagated to managedcluster enabling cross-tenant managedclusterset join | Red Hat | Multicluster Engine for Kubernetes | High | 7.1 | 2026-08-13 16:36:45 | Deep Dive |