Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-58314Highcode.gitea.io/gitea: Gitea: Two SSRF findingsCVE-2026-58436Highcode.gitea.io/gitea: Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requestsCVE-2026-56657Mediumcode.gitea.io/gitea: Gitea SSH Key Parser Denial of ServiceCVE-2026-58437Highcode.gitea.io/gitea: Gitea: Repository Visibility Manipulation via Git Push OptionsCVE-2026-55987Highcode.gitea.io/gitea: Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)CVE-2026-58435Mediumcode.gitea.io/gitea: Gitea LFS Deploy-Key Privilege EscalationCVE-2026-58420Mediumgitea.dev: Gitea: Local File Inclusion via file:// URI in Migration RestoreCVE-2026-55984Lowcode.gitea.io/gitea: Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of ServiceCVE-2026-55982Mediumcode.gitea.io/gitea: Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token ScopesCVE-2026-58434Lowcode.gitea.io/gitea: Gitea: Private Repository Metadata Remains Accessible After Access RevocationCVE-2026-54481Highcode.gitea.io/gitea: Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config overrideCVE-2026-58417Mediumgitea.dev: Gitea: REST API exposes organization membership of private organizations to publicCVE-2026-50105Mediumcode.gitea.io/gitea: Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)CVE-2026-58416Mediumgitea.dev: Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)CVE-2026-42931Mediumcode.gitea.io/gitea: Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag EndpointCVE-2026-58445Lowcode.gitea.io/gitea: Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel APICVE-2026-58444Mediumcode.gitea.io/gitea: Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository…CVE-2026-58443Criticalcode.gitea.io/gitea: Gitea: Public-only repository tokens can update private PR head branchesCVE-2026-58442Mediumcode.gitea.io/gitea: Gitea: Repository migration SSRF via multi-answer DNS allow-list bypassCVE-2026-58441Mediumcode.gitea.io/gitea: Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURLCVE-2026-58438Lowgitea.dev: Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot accessCVE-2026-58426Criticalcode.gitea.io/gitea: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state writeCVE-2026-58424Highcode.gitea.io/gitea: Gitea: Permanent Fork PR Workflow Approval Gate BypassCVE-2026-58423Highcode.gitea.io/gitea: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositoriesCVE-2026-58421Highcode.gitea.io/gitea: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

Stop the waste.
Protect your environment with Kodem.