π¨ CVE-2026-24059
The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked read:user-scoped token can therefore mint a registration token and register a malicious Actions runner that executes workflow jobs with access to repository secrets and source code.
π@cveNotify
The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked read:user-scoped token can therefore mint a registration token and register a malicious Actions runner that executes workflow jobs with access to repository secrets and source code.
π@cveNotify
Gitea
Gitea 1.25.5 is released | Gitea Blog
We're excited to announce the release of Gitea 1.25.5! We strongly recommend all users upgrade to this version, as it includes important security fixes, numerous bug fixes, and overall stability improvements.
π¨ CVE-2026-24791
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
π@cveNotify
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
π@cveNotify
Gitea
Gitea 1.26.2 is released | Gitea Blog
We are excited to announce the release of Gitea 1.26.2! We strongly recommend all users upgrade to this version, as it contains a number of security fixes alongside important bug fixes and stability improvements.
π¨ CVE-2026-42931
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
π@cveNotify
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
π@cveNotify
π¨ CVE-2026-50105
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
π@cveNotify
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
π@cveNotify
π¨ CVE-2026-54481
Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)
π@cveNotify
Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)
π@cveNotify
π¨ CVE-2026-55402
CVE-2026-55402 is an out of bounds read vulnerability in Secure Access
servers prior to version 14.57. Attackers with an βin the middleβ
position can send specially crafted data to a server causing a
persistent denial of service.
π@cveNotify
CVE-2026-55402 is an out of bounds read vulnerability in Secure Access
servers prior to version 14.57. Attackers with an βin the middleβ
position can send specially crafted data to a server causing a
persistent denial of service.
π@cveNotify
Absolute
CVE-2026-55402 | Absolute Security
A high severity vulnerability in the Secure Access server installer prior to 14.57
π¨ CVE-2026-55982
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
π@cveNotify
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
π@cveNotify
π¨ CVE-2026-55984
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
π@cveNotify
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
π@cveNotify
π¨ CVE-2026-55986
Email Management API Bypasses ManageCredentials Feature Restrictions
π@cveNotify
Email Management API Bypasses ManageCredentials Feature Restrictions
π@cveNotify
π¨ CVE-2026-55987
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
π@cveNotify
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
π@cveNotify
π¨ CVE-2026-56443
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) β residual after CVE-2026-25714 / PR #37118
π@cveNotify
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) β residual after CVE-2026-25714 / PR #37118
π@cveNotify
π¨ CVE-2026-56755
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
π@cveNotify
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
π@cveNotify
π¨ CVE-2026-57886
Cross-repository issue/comment attachment re-linking can expose private attachment content
π@cveNotify
Cross-repository issue/comment attachment re-linking can expose private attachment content
π@cveNotify
π¨ CVE-2026-57894
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
π@cveNotify
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
π@cveNotify
π¨ CVE-2026-57897
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
π@cveNotify
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
π@cveNotify
π¨ CVE-2026-58416
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
π@cveNotify
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
π@cveNotify