检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-3PWW-VCVM-3GMJ CVE-2026-27761 | Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:30 | 2026-07-22 04:30 |
| GHSA-2M9V-5Q2G-58VQ CVE-2026-28740 | Gitea: Git LFS object reuse allows non-Code access to authorize private source objects |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogitea.dev |
| 已审查 |
| 2026-07-22 04:29 |
| 2026-07-22 04:29 |
| GHSA-F75J-4CW6-RMX4 CVE-2026-20896 | Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` | 严重 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:28 | 2026-07-22 04:28 |
| GHSA-2R5C-GW76-RH3W CVE-2026-22874 | Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter | 严重 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:27 | 2026-07-22 04:27 |
| GHSA-RJVX-X5H2-6PX5 | Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:26 | 2026-07-22 04:26 |
| GHSA-683J-3FF6-HH2X CVE-2026-56654 | Gitea: Privilege Escalation via Access Token Scope Escalation in API | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:24 | 2026-07-22 04:24 |
| GHSA-6HM7-3PWJ-22RM CVE-2026-56755 | Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:24 | 2026-07-22 04:24 |
| GHSA-P4MJ-98MV-XQ26 CVE-2026-58507 | Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:23 | 2026-07-22 04:23 |
| GHSA-6C6R-5XR4-CR5M CVE-2026-57886 | Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:22 | 2026-07-22 04:22 |
| GHSA-X77V-Q46J-393G CVE-2026-23603 | Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim | 低危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:22 | 2026-07-22 04:22 |
| GHSA-VXV2-8J6R-PCPG CVE-2026-58425 | Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:21 | 2026-07-22 04:21 |
| GHSA-9MQ6-MQJJ-C2C5 CVE-2026-59763 | Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:20 | 2026-07-22 04:20 |
| GHSA-RGV6-XP99-6MGJ CVE-2026-56750 | Gitea Remember-Me Token Theft Not Invalidating Attacker Session | 严重 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:20 | 2026-07-22 04:20 |
| GHSA-Q9PG-JJ6X-J9P6 CVE-2026-58432 | Gitea: draft release attachment disclosure via missing web authorization | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:19 | 2026-07-22 04:19 |
| GHSA-25GQ-J9JX-43PG CVE-2026-58428 | Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:18 | 2026-07-22 04:18 |
| GHSA-7P4H-3GXQ-X3H3 CVE-2026-56443 | Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:17 | 2026-07-22 04:17 |
| GHSA-W5PG-649R-P6GG CVE-2026-58439 | Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:14 | 2026-07-22 04:15 |
| GHSA-QF2F-QH6P-7V89 CVE-2026-59766 | Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-07-22 04:13 | 2026-07-22 04:13 |
| GHSA-66M4-5JJR-2RG5 CVE-2026-58440 | Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content | 中危 | Gogitea.dev | 已审查 | 2026-07-22 04:11 | 2026-07-22 04:11 |
| GHSA-956X-8GVW-WG5V | GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()` | 高危 | PyPIGitPython | 已审查 | 2026-07-22 04:10 | 2026-07-22 04:10 |
| GHSA-2F96-G7MH-G2HX | GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist | 高危 | PyPIGitPython | 已审查 | 2026-07-22 03:43 | 2026-07-22 03:43 |
| GHSA-V396-V7Q4-X2QJ | GitPython unsafe clone option gate bypass through joined short options | 高危 | PyPIGitPython | 已审查 | 2026-07-22 03:43 | 2026-07-22 03:43 |
| GHSA-2P49-HGCM-8545 CVE-2026-73650 | SVGO removeScripts plugin leaves some executable scripts intact | 高危 | npmsvgo | 已审查 | 2026-07-22 03:42 | 2026-08-14 02:08 |
| GHSA-C2J3-45GR-MQC4 | DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements. | 低危 | npmdompurify | 已审查 | 2026-07-22 03:41 | 2026-07-22 03:41 |
| GHSA-MHM7-754M-9P8W | jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)` | 中危 | Mavencom.fasterxml.jackson.core:jackson-databind | 已审查 | 2026-07-22 03:40 | 2026-07-22 03:40 |