Go Vulnerability Database
Data about new vulnerabilities come directly from Go package maintainers or sources such as MITRE and GitHub. Reports are curated by the Go Security team. Learn more at go.dev/security/vuln.
Search
Recent Reports
- CVE-2026-58443, GHSA-xxjv-752h-3vp2
- Affects: gitea.dev
- Published: Jul 27, 2026
- Unreviewed
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev
- CVE-2026-58438, GHSA-xv9x-fj9g-vj6h
- Affects: gitea.dev
- Published: Jul 27, 2026
- Unreviewed
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev
- CVE-2026-58441, GHSA-xmj7-xj85-hfc3
- Affects: gitea.dev
- Published: Jul 27, 2026
- Unreviewed
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev
- CVE-2026-23603, GHSA-x77v-q46j-393g
- Affects: gitea.dev
- Published: Jul 27, 2026
- Unreviewed
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev
- CVE-2026-42931, GHSA-wwqq-x6w4-frm2
- Affects: gitea.dev
- Published: Jul 27, 2026
- Unreviewed
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev
If you don't see an existing, public Go vulnerability in a publicly importable package in our database, please let us know.