Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile
CWECWE 284VNDGiteaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 21:16Z
CRIT
CVE-2026-26247 — Gitea: versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
CVSSv3.1 9.1 (CRITICAL) · EPSS 6th percentile
CWECWE 284VNDGiteaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 21:16Z
CRIT
CVE-2026-26232 — Gitea: versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use
Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.
CVSSv3.1 9.1 (CRITICAL) · EPSS 6th percentile
CWECWE 294VNDGiteaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 21:16Z
HIGH
CVE-2026-26231 — Gitea: versions up to and including 1.26.1 allow the Allow edits from maintainers permission
Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.
CVSSv3.1 8.5 (HIGH)
CWECWE 863VNDGiteaTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-03
2026-07-03 21:16Z
CRIT
CVE-2026-25718 — Gitea: versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.
CVSSv3.1 8.1 (HIGH)
CWECWE 284VNDGiteaTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-03
2026-07-03 21:16Z
CRIT
CVE-2026-22547 — Gitea: versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template
Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or object format values.
CVSSv3.1 9.1 (CRITICAL) · EPSS 6th percentile
CWECWE 20VNDGiteaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 21:16Z
CRIT
CVE-2026-20896 — Gitea: Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 284VNDGiteaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 21:16Z
CRIT
CVE-2026-20706 — Gitea: versions up to and including 1.26.1 allow repository archive downloads to bypass token
Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.
CVSSv3.1 9.1 (CRITICAL) · EPSS 17th percentile
CWECWE 284VNDGiteaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 21:16Z
HIGH
CVE-2026-12481 — A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper
A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()` function fails to enforce the safe-mode guard when `safe_mode` is set to `None`, which is the default value when `from_config()` is called outside of a `SafeModeScope` context. This logic error conflates `None` (unset/default-deny) with `False` (explicitly disabled), by
CVSSv3.1 8.8 (HIGH)
CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-03
2026-07-03 15:16Z
HIGH
CVE-2026-14460 — Authorization: Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection.
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection.
This issue affects pardus-software: from <= 1.0.4 before 1.0.5.
CVSSv3.1 8.8 (HIGH)
CWECWE 862TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-03
2026-07-03 15:16Z
HIGH
CVE-2026-14459 — Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM
Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection.
This issue affects pardus-software: from <= 1.0.4 before 1.0.5.
CVSSv3.1 8.8 (HIGH)
CWECWE 88TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-03
2026-07-03 13:17Z
CRIT
CVE-2026-56015 — Net: Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded
Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length.
add() passes the prefix string to the trie builder addPrefixToTrie() without checking it against the address width.
addPrefixToTrie() then walks the prefix buffer by prefix_length bits, reading prefix[byte] for byte up to prefix_len/8, where prefix is the 4-byte (IPv4) or 16-byte (IPv6) packed address. A prefix length greater than 32 for IPv4 or 128 for IPv6, for exam
CVSSv3.1 9.1 (CRITICAL) · EPSS 13th percentile
CWECWE 125TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 11:16Z
HIGH
CVE-2026-10055 — Eclipse: In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL
In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and returns the full response body to the caller.
Because the destination URL is neither validated nor allowlisted, a remote attacker with access to the Theia service connection can issue server-side HTTP requests to localhost or other backend-reach
CVSSv3.1 8.5 (HIGH)
CWECWE 918CWECWE 200VNDEclipseTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-03
2026-07-03 11:16Z
HIGH
CVE-2026-10054 — Eclipse: In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged
In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shell-terminal, /services/terminals/:id) without service-level authentication.
WebSocket origin validation in @theia/core is fail-open: connections are accepted when the Origin header is missing or when no THEIA_HOSTS allowlist is configured (the default). The Socket.IO integration additionally replaces the real Origin header with a client
CVSSv3.1 8.8 (HIGH)
CWECWE 306CWECWE 1385VNDEclipseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-03
2026-07-03 10:16Z
CRIT
CVE-2026-4321 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows SQL Injection.
This issue affects Destekz: through 02062026. NOTE: The vendor was contacted and it was learned that the product is not supported.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 10:00Z
HIGH
Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign
Kaspersky Securelist·securelist.com
Kaspersky disclosed a phishing campaign by APT group Armored Likho (Eagle Werewolf) deploying BusySnake Stealer, a previously undocumented Python-based infostealer targeting Windows systems. The campaign uses spear-phishing with malicious archives containing NSIS droppers or LNK files exploiting ZDI-CAN-25373, leading to multi-stage payload delivery via GitHub-hosted repositories. BusySnake Stealer features PyArmor Pro obfuscation, credential harvesting from Firefox/Chromium browsers via DPAPI/NSS decryption, clipboard logging, screenshot capture, 2FA secret scraping, cryptocurrency wallet theft, Telegram session exfiltration, and reverse SSH tunneling via C2 commands.
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library).
This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018.
Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.
CVSSv3.1 9.8 (CRITICAL) · EPSS 3th percentile
CWECWE 611VNDApacheTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 08:16Z
CRIT
CVE-2026-14544 — HPLIP: This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate
A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 190VNDHplipTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 07:16Z
CRIT
CVE-2026-9079 — libcurl had a flaw that when instructed to clear proxy authentication credentials which made
libcurl had a flaw that when instructed to clear proxy authentication
credentials which made it not do so, leaving the old credentials around to get
used for subsequent transfers that should not know nor use them.
CVSSv3.1 9.8 (CRITICAL) · EPSS 16th percentile
TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 07:16Z
CRIT
CVE-2026-8927 — When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl
When reusing a libcurl handle for sequential transfers driven by
environment-variable proxy configuration, libcurl fails to clear the proxy
authentication state between requests. Specifically, if the initial transfer
authenticates against `proxyA` using Digest auth, a subsequent transfer routed
through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended
solely for `proxyA`.
CVSSv3.1 9.1 (CRITICAL) · EPSS 16th percentile
TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 07:16Z
CRIT
CVE-2026-8926 — When asking curl to use a `.netrc` file to find credentials and at the
When asking curl to use a `.netrc` file to find credentials and at the same
time specifying a URL with a username(without a password), like
`https://user@example.com/`, curl could wrongly get and use the password for
*another* user set in the `.netrc` file for that host if such a one exists and
there is no match for the specified user.
CVSSv3.1 9.1 (CRITICAL) · EPSS 9th percentile
TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 07:16Z
CRIT
CVE-2026-8925 — The curl logic that works with SASL authentication could end up cleaning up the
The curl logic that works with SASL authentication could end up cleaning up
the GSASL context *twice* without clearing the pointer in between, making it
`free()` the same pointer twice.
CVSSv3.1 9.8 (CRITICAL) · EPSS 16th percentile
TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 07:16Z
CRIT
CVE-2026-8924 — A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set
'super cookies' that bypass the Public Suffix List check. This enables an
attacker-controlled origin to inject cookies that curl subsequently scopes and
transmits to unrelated third-party domains.
CVSSv3.1 9.1 (CRITICAL) · EPSS 12th percentile