Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-58418Mediumcode.gitea.io/gitea: Gitea: SSRF via HTTP Redirect in Repository MigrationCVE-2026-27761Mediumcode.gitea.io/gitea: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit dataCVE-2026-28740Highgitea.dev: Gitea: Git LFS object reuse allows non-Code access to authorize private source objectsCVE-2026-20896Criticalcode.gitea.io/gitea: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`CVE-2026-22874Criticalcode.gitea.io/gitea: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default FilterGHSA-RJVX-X5H2-6PX5Mediumcode.gitea.io/gitea: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation RestrictionsCVE-2026-56654Highcode.gitea.io/gitea: Gitea: Privilege Escalation via Access Token Scope Escalation in APICVE-2026-56755Highcode.gitea.io/gitea: Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package UploadCVE-2026-58507Mediumcode.gitea.io/gitea: Gitea: Private Repository Existence Disclosure via go-get Meta EndpointCVE-2026-57886Mediumcode.gitea.io/gitea: Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment contentCVE-2026-23603Lowcode.gitea.io/gitea: Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claimCVE-2026-58425Mediumcode.gitea.io/gitea: Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)CVE-2026-59763Mediumcode.gitea.io/gitea: Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploadsCVE-2026-56750Criticalcode.gitea.io/gitea: Gitea Remember-Me Token Theft Not Invalidating Attacker SessionCVE-2026-58432Mediumcode.gitea.io/gitea: Gitea: draft release attachment disclosure via missing web authorizationCVE-2026-58428Mediumcode.gitea.io/gitea: Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)CVE-2026-56443Mediumcode.gitea.io/gitea: Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR…CVE-2026-58439Highcode.gitea.io/gitea: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval FlagCVE-2026-59766Mediumcode.gitea.io/gitea: Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private…CVE-2026-58440Mediumgitea.dev: Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo…GHSA-956X-8GVW-WG5VHighGitPython: GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via…GHSA-2F96-G7MH-G2HXHighGitPython: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklistGHSA-V396-V7Q4-X2QJHighGitPython: GitPython unsafe clone option gate bypass through joined short optionsGHSA-2P49-HGCM-8545Highsvgo: SVGO removeScripts plugin leaves some executable scripts intactGHSA-C2J3-45GR-MQC4Lowdompurify: DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.

Stop the waste.
Protect your environment with Kodem.