π¨ CVE-2026-24059
The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked read:user-scoped token can therefore mint a registration token and register a malicious Actions runner that executes workflow jobs with access to repository secrets and source code.
π@cveNotify
The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked read:user-scoped token can therefore mint a registration token and register a malicious Actions runner that executes workflow jobs with access to repository secrets and source code.
π@cveNotify
Gitea Blog
Gitea 1.25.5 is released
We're excited to announce the release of Gitea 1.25.5 We strongly recommend all users upgrade to this version, as it includes important security fixes, numerous bug fixes, and overall stability improvements. CVE 2026 25779: Prevent redirect bypasses via backslashβ¦
π¨ CVE-2026-24791
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
π@cveNotify
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
π@cveNotify
Gitea Blog
Gitea 1.26.2 is released
We are excited to announce the release of Gitea 1.26.2 We strongly recommend all users upgrade to this version, as it contains a number of security fixes alongside important bug fixes and stability improvements. CVE 2026 27783: fix permissions : Fix readingβ¦
π¨ CVE-2026-42931
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
π@cveNotify
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
π@cveNotify
π¨ CVE-2026-50105
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
π@cveNotify
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
π@cveNotify
π¨ CVE-2026-54481
Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)
π@cveNotify
Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)
π@cveNotify
π¨ CVE-2026-55982
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
π@cveNotify
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
π@cveNotify
π¨ CVE-2026-55984
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
π@cveNotify
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
π@cveNotify
π¨ CVE-2026-55986
Email Management API Bypasses ManageCredentials Feature Restrictions
π@cveNotify
Email Management API Bypasses ManageCredentials Feature Restrictions
π@cveNotify
π¨ CVE-2026-55987
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
π@cveNotify
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
π@cveNotify
π¨ CVE-2026-56443
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) β residual after CVE-2026-25714 / PR #37118
π@cveNotify
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) β residual after CVE-2026-25714 / PR #37118
π@cveNotify
π¨ CVE-2026-56755
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
π@cveNotify
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
π@cveNotify
π¨ CVE-2026-57886
Cross-repository issue/comment attachment re-linking can expose private attachment content
π@cveNotify
Cross-repository issue/comment attachment re-linking can expose private attachment content
π@cveNotify
π¨ CVE-2026-57894
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
π@cveNotify
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
π@cveNotify
π¨ CVE-2026-57897
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
π@cveNotify
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
π@cveNotify
π¨ CVE-2026-58416
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
π@cveNotify
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
π@cveNotify
π¨ CVE-2026-58417
REST API exposes organization membership of private organizations to public
π@cveNotify
REST API exposes organization membership of private organizations to public
π@cveNotify
π¨ CVE-2026-58425
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
π@cveNotify
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
π@cveNotify