2026 CVE Vulnerabilities
57,111 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27771 | HIGH | 8.2 | 40.7% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which c... |
| CVE-2026-27761 | MEDIUM | 4.3 | 0.4% | Jul 3, 2026 | Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope ... |
| CVE-2026-27660 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permissio... |
| CVE-2026-27657 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 allow a user to change another user's primary email address. |
| CVE-2026-26307 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume serve... |
| CVE-2026-26292 | CRITICAL | 9.8 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing ... |
| CVE-2026-26247 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowi... |
| CVE-2026-26232 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during... |
| CVE-2026-26231 | HIGH | 8.5 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to... |
| CVE-2026-25782 | MEDIUM | 5.3 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the requ... |
| CVE-2026-25779 | MEDIUM | 6.1 | 0.2% | Jul 3, 2026 | Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect... |
| CVE-2026-25718 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processi... |
| CVE-2026-25714 | MEDIUM | 4.3 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization... |
| CVE-2026-25712 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and ... |
| CVE-2026-25038 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea 1.26.2 allows unauthorized users to access labels of private organizations. |
| CVE-2026-24690 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches. |
| CVE-2026-24451 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing ... |
| CVE-2026-22874 | CRITICAL | 9.6 | 0.5% | Jul 3, 2026 | Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering. |
| CVE-2026-22555 | HIGH | 8.1 | 0.3% | Jul 3, 2026 | Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCrea... |
| CVE-2026-22547 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited templa... |
| CVE-2026-20909 | MEDIUM | 5.3 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries. |
| CVE-2026-20896 | CRITICAL | 9.8 | 0.8% | Jul 3, 2026 | Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any sour... |
| CVE-2026-20779 | HIGH | 7.1 | 0.5% | Jul 3, 2026 | Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be ac... |
| CVE-2026-20706 | CRITICAL | 9.1 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web arc... |
| CVE-2026-14611 | MEDIUM | 5.3 | 0.3% | Jul 3, 2026 | A vulnerability has been found in DeepMyst Mysti up to 0.4.0. The affected element is the function initProjectMemory of ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now