| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents |
| SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata |
| CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell. |
| REST API exposes organization membership of private organizations to public |
| OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) |
| Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) |
| Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints |
| Public-only API token restriction is not enforced on team API routes |
| Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea |
| Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting |
| Gitea LFS Deploy-Key Privilege Escalation |
| ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests |
| Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access |
| Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`) |
| SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL |
| Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) |
| GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private |
| A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknown function of the file utilities_configurationsave.cgi of the component Web Management Interface. Executing a manipulation of the argument sessionKey can lead to denial of service. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. |
| The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker (v2.0.22) that listens on all network interfaces with anonymous access enabled and no firewall restriction. An attacker with access to the Bridge's network can read device data and control connected lights. |
| IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from improperly validating client data. By sending malformed requests to one of the host servers, a remote attacker could leverage this vulnerability to cause a denial-of-server (DoS) for that server. |