2026 CVE Vulnerabilities

57,111 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27771HIGH8.2Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which c...
CVE-2026-27761MEDIUM4.3Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope ...
CVE-2026-27660HIGH7.5Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permissio...
CVE-2026-27657HIGH7.5Gitea versions before 1.25.5 allow a user to change another user's primary email address.
CVE-2026-26307HIGH7.5Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume serve...
CVE-2026-26292CRITICAL9.8Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing ...
CVE-2026-26247CRITICAL9.1Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowi...
CVE-2026-26232CRITICAL9.1Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during...
CVE-2026-26231HIGH8.5Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to...
CVE-2026-25782MEDIUM5.3Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the requ...
CVE-2026-25779MEDIUM6.1Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect...
CVE-2026-25718CRITICAL9.1Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processi...
CVE-2026-25714MEDIUM4.3Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization...
CVE-2026-25712HIGH7.5Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and ...
CVE-2026-25038HIGH7.5Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
CVE-2026-24690HIGH7.5Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
CVE-2026-24451HIGH7.5Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing ...
CVE-2026-22874CRITICAL9.6Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
CVE-2026-22555HIGH8.1Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCrea...
CVE-2026-22547CRITICAL9.1Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited templa...
CVE-2026-20909MEDIUM5.3Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
CVE-2026-20896CRITICAL9.8Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any sour...
CVE-2026-20779HIGH7.1Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be ac...
CVE-2026-20706CRITICAL9.1Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web arc...
CVE-2026-14611MEDIUM5.3A vulnerability has been found in DeepMyst Mysti up to 0.4.0. The affected element is the function initProjectMemory of ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now