检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-FW57-JGCH-PGF3 CVE-2026-58436 | Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 05:15 | 2026-07-22 05:15 |
| GHSA-4XJF-493Q-98P3 CVE-2026-56657 | Gitea SSH Key Parser Denial of Service |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Gocode.gitea.io/gitea |
| 已审查 |
| 2026-07-22 05:09 |
| 2026-07-22 05:09 |
| GHSA-8P9H-49RC-QGXJ CVE-2026-58437 | Gitea: Repository Visibility Manipulation via Git Push Options | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 05:02 | 2026-07-22 05:02 |
| GHSA-VRHC-JJFC-M3M3 CVE-2026-55987 | Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 05:02 | 2026-07-22 05:02 |
| GHSA-RH79-75QM-GWJR CVE-2026-58435 | Gitea LFS Deploy-Key Privilege Escalation | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 05:00 | 2026-07-22 05:00 |
| GHSA-5GGR-2F2H-JMVM CVE-2026-58420 | Gitea: Local File Inclusion via file:// URI in Migration Restore | 中危 | Gogitea.dev | 已审查 | 2026-07-22 04:59 | 2026-07-22 04:59 |
| GHSA-M932-CRVM-GCP5 CVE-2026-55984 | Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service | 低危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:59 | 2026-07-22 04:59 |
| GHSA-MG4F-X9V4-6H2P CVE-2026-55982 | Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:42 | 2026-07-22 04:42 |
| GHSA-J2W3-9C3R-G83Q CVE-2026-58434 | Gitea: Private Repository Metadata Remains Accessible After Access Revocation | 低危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:41 | 2026-07-22 04:41 |
| GHSA-94V3-77J7-VM48 CVE-2026-54481 | Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:41 | 2026-07-22 04:41 |
| GHSA-JR5X-6H83-WRXF CVE-2026-58417 | Gitea: REST API exposes organization membership of private organizations to public | 中危 | Gogitea.dev | 已审查 | 2026-07-22 04:40 | 2026-07-22 04:40 |
| GHSA-6CQF-375W-639G CVE-2026-50105 | Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:40 | 2026-07-22 04:40 |
| GHSA-FJ8V-HJWV-QM88 CVE-2026-58416 | Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) | 中危 | Gogitea.dev | 已审查 | 2026-07-22 04:40 | 2026-07-22 04:40 |
| GHSA-WWQQ-X6W4-FRM2 CVE-2026-42931 | Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:39 | 2026-07-22 04:39 |
| GHSA-PGQF-926R-548M CVE-2026-58445 | Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API | 低危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:39 | 2026-07-22 04:39 |
| GHSA-CP3Q-VRJ2-GHHH CVE-2026-58444 | Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:38 | 2026-07-22 04:38 |
| GHSA-XXJV-752H-3VP2 CVE-2026-58443 | Gitea: Public-only repository tokens can update private PR head branches | 严重 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:38 | 2026-07-22 04:38 |
| GHSA-H2X6-G7Q6-344V CVE-2026-58442 | Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:37 | 2026-07-22 04:37 |
| GHSA-XMJ7-XJ85-HFC3 CVE-2026-58441 | Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:37 | 2026-07-22 04:37 |
| GHSA-XV9X-FJ9G-VJ6H CVE-2026-58438 | Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access | 低危 | Gogitea.dev | 已审查 | 2026-07-22 04:36 | 2026-07-22 04:36 |
| GHSA-HG5R-VQ93-9FV6 CVE-2026-58426 | Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write | 严重 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:36 | 2026-07-22 04:36 |
| GHSA-777R-4V59-6486 CVE-2026-58424 | Gitea: Permanent Fork PR Workflow Approval Gate Bypass | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:35 | 2026-07-22 04:35 |
| GHSA-7WVC-RVP7-W99X CVE-2026-58423 | Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:35 | 2026-07-22 04:35 |
| GHSA-V96J-25GV-G2W9 CVE-2026-58421 | Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:34 | 2026-07-22 04:34 |
| GHSA-RQHX-647V-WX32 CVE-2026-58418 | Gitea: SSRF via HTTP Redirect in Repository Migration | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:33 | 2026-07-22 04:33 |