CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`) | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot accessCross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access CWE-862Aug 13, 2026 | CVSS-v4.0 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Public-only API token restriction is not enforced on team API routesPublic-only API token restriction is not enforced on team API routes CWE-863Aug 13, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 | CVSS- | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Local File Inclusion via file:// URI in Migration RestoreLocal File Inclusion via file:// URI in Migration Restore | CVSS-v4.0 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
REST API exposes organization membership of private organizations to publicREST API exposes organization membership of private organizations to public | CVSS-v4.0 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-58416HIGH | Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) | CVSS7.1v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-28740HIGH | Gitea LFS object reuse bypasses Code-unit authorizationGitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access. | CVSS7.1v3.1 | EPSS0.267% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |