<?xml version="1.0" encoding="utf-8"?>
            <?xml-stylesheet type="text/xsl" href="/preview.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
<atom:link href="https://rsseverything.com/ja/feed/0d9cc5d3-20c2-4021-bda4-45769f953be5.xml" rel="self" type="application/rss+xml" />
    <title>Vulnerability Reports - Go Packages</title>
    <link>https://pkg.go.dev/vuln/list</link>
    <description><![CDATA[Go is an open source programming language that makes it easy to build simple, reliable, and efficient software.]]></description>
    <lastBuildDate>Fri, 07 Aug 2026 12:10:39 +0000</lastBuildDate>
    <generator>Rss Everything</generator>
    <ttl>360</ttl>



<item>




<guid isPermaLink="false">796dc54c138fc776989d46cd9896c989</guid>
<pubDate>Mon, 27 Jul 2026 22:27:26 +0000</pubDate>
<title>GO-2026-6086</title>
<link>https://pkg.go.dev/vuln/GO-2026-6086</link>
<description><![CDATA[CVE-2026-58443, GHSA-xxjv-752h-3vp2, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: Public-only repository tokens can update private PR head branches in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">6560b7d0fbf72647dcb4d569172660f9</guid>
<pubDate>Mon, 27 Jul 2026 22:27:18 +0000</pubDate>
<title>GO-2026-6085</title>
<link>https://pkg.go.dev/vuln/GO-2026-6085</link>
<description><![CDATA[CVE-2026-58438, GHSA-xv9x-fj9g-vj6h, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">3a8142737730b76dbff657e588216d5a</guid>
<pubDate>Mon, 27 Jul 2026 22:27:11 +0000</pubDate>
<title>GO-2026-6084</title>
<link>https://pkg.go.dev/vuln/GO-2026-6084</link>
<description><![CDATA[CVE-2026-58441, GHSA-xmj7-xj85-hfc3, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">33287ac2ea44b8f1f62ea1c7e596a30a</guid>
<pubDate>Mon, 27 Jul 2026 22:27:06 +0000</pubDate>
<title>GO-2026-6083</title>
<link>https://pkg.go.dev/vuln/GO-2026-6083</link>
<description><![CDATA[CVE-2026-23603, GHSA-x77v-q46j-393g, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">07cd3db8c7955b63ba3ea3bdfb3278c0</guid>
<pubDate>Mon, 27 Jul 2026 22:27:00 +0000</pubDate>
<title>GO-2026-6082</title>
<link>https://pkg.go.dev/vuln/GO-2026-6082</link>
<description><![CDATA[CVE-2026-42931, GHSA-wwqq-x6w4-frm2, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">81c7e8e080bbc696546d218b2b783a88</guid>
<pubDate>Mon, 27 Jul 2026 22:26:53 +0000</pubDate>
<title>GO-2026-6081</title>
<link>https://pkg.go.dev/vuln/GO-2026-6081</link>
<description><![CDATA[CVE-2026-24451, GHSA-wrf9-r3h7-7x5v, code.gitea.io/gitea, Published: Jul 27, 2026, Unreviewed, Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">7b9fe320110dc292689d5e51119d82a9</guid>
<pubDate>Mon, 27 Jul 2026 22:26:45 +0000</pubDate>
<title>GO-2026-6080</title>
<link>https://pkg.go.dev/vuln/GO-2026-6080</link>
<description><![CDATA[CVE-2026-58439, GHSA-w5pg-649r-p6gg, code.gitea.io/gitea, Published: Jul 27, 2026, Unreviewed, Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: code.gitea.io/gitea before v1.27.0.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">d0bbd81783cb1d8d227be91b114dc71f</guid>
<pubDate>Mon, 27 Jul 2026 22:26:40 +0000</pubDate>
<title>GO-2026-6079</title>
<link>https://pkg.go.dev/vuln/GO-2026-6079</link>
<description><![CDATA[CVE-2026-58425, GHSA-vxv2-8j6r-pcpg, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">02339c2d850d11e157e57dd4ffd5dcfd</guid>
<pubDate>Mon, 27 Jul 2026 22:26:33 +0000</pubDate>
<title>GO-2026-6078</title>
<link>https://pkg.go.dev/vuln/GO-2026-6078</link>
<description><![CDATA[CVE-2026-55987, GHSA-vrhc-jjfc-m3m3, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">01a4dddc2c8b7789fd7ccc4013ed1db5</guid>
<pubDate>Mon, 27 Jul 2026 22:26:31 +0000</pubDate>
<title>GO-2026-6077</title>
<link>https://pkg.go.dev/vuln/GO-2026-6077</link>
<description><![CDATA[CVE-2026-58421, GHSA-v96j-25gv-g2w9, code.gitea.io/gitea, Published: Jul 27, 2026, Unreviewed, Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">33552f424cfdf0dbb288bc60d7f4b763</guid>
<pubDate>Mon, 27 Jul 2026 22:26:21 +0000</pubDate>
<title>GO-2026-6076</title>
<link>https://pkg.go.dev/vuln/GO-2026-6076</link>
<description><![CDATA[CVE-2026-25038, GHSA-v73x-hx65-6pf4, code.gitea.io/gitea, Published: Jul 27, 2026, Unreviewed, Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">534bb3d86819f686a19e2f99f0ccc170</guid>
<pubDate>Mon, 27 Jul 2026 22:26:17 +0000</pubDate>
<title>GO-2026-6075</title>
<link>https://pkg.go.dev/vuln/GO-2026-6075</link>
<description><![CDATA[CVE-2026-58418, GHSA-rqhx-647v-wx32, code.gitea.io/gitea, Published: Jul 27, 2026, Unreviewed, Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">a06c5077f0ebb79b11acada0a927ce5c</guid>
<pubDate>Mon, 27 Jul 2026 22:26:15 +0000</pubDate>
<title>GO-2026-6074</title>
<link>https://pkg.go.dev/vuln/GO-2026-6074</link>
<description><![CDATA[GHSA-rjvx-x5h2-6px5, code.gitea.io/gitea, Published: Jul 27, 2026, Unreviewed, Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">a19def97b48d29943f5b9132b1725526</guid>
<pubDate>Mon, 27 Jul 2026 22:26:03 +0000</pubDate>
<title>GO-2026-6073</title>
<link>https://pkg.go.dev/vuln/GO-2026-6073</link>
<description><![CDATA[CVE-2026-58435, GHSA-rh79-75qm-gwjr, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea LFS Deploy-Key Privilege Escalation in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">1640d7091bb279a76f11ecb1d7f8b256</guid>
<pubDate>Mon, 27 Jul 2026 22:26:02 +0000</pubDate>
<title>GO-2026-6072</title>
<link>https://pkg.go.dev/vuln/GO-2026-6072</link>
<description><![CDATA[CVE-2026-56750, GHSA-rgv6-xp99-6mgj, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">a879988a727158ed708134c792e06034</guid>
<pubDate>Mon, 27 Jul 2026 22:25:52 +0000</pubDate>
<title>GO-2026-6071</title>
<link>https://pkg.go.dev/vuln/GO-2026-6071</link>
<description><![CDATA[CVE-2026-59766, GHSA-qf2f-qh6p-7v89, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">dbb68268ce864202f802af7d9598583f</guid>
<pubDate>Mon, 27 Jul 2026 22:25:47 +0000</pubDate>
<title>GO-2026-6070</title>
<link>https://pkg.go.dev/vuln/GO-2026-6070</link>
<description><![CDATA[CVE-2026-58432, GHSA-q9pg-jj6x-j9p6, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: draft release attachment disclosure via missing web authorization in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">2406f61fdafa529b1da9209a0165568e</guid>
<pubDate>Mon, 27 Jul 2026 22:25:39 +0000</pubDate>
<title>GO-2026-6069</title>
<link>https://pkg.go.dev/vuln/GO-2026-6069</link>
<description><![CDATA[CVE-2026-58510, GHSA-q423-49rw-g9mh, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">569065d15fcab7d489b28438b8e29e6e</guid>
<pubDate>Mon, 27 Jul 2026 22:25:33 +0000</pubDate>
<title>GO-2026-6068</title>
<link>https://pkg.go.dev/vuln/GO-2026-6068</link>
<description><![CDATA[CVE-2026-58427, GHSA-prr9-9mp4-5gp2, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">954530221a82004f88e573d8a7abe867</guid>
<pubDate>Mon, 27 Jul 2026 22:25:33 +0000</pubDate>
<title>GO-2026-6067</title>
<link>https://pkg.go.dev/vuln/GO-2026-6067</link>
<description><![CDATA[CVE-2026-58445, GHSA-pgqf-926r-548m, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">29f4e7935cfb333a966478de3dc7ee11</guid>
<pubDate>Mon, 27 Jul 2026 22:25:21 +0000</pubDate>
<title>GO-2026-6066</title>
<link>https://pkg.go.dev/vuln/GO-2026-6066</link>
<description><![CDATA[CVE-2026-58507, GHSA-p4mj-98mv-xq26, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">5797c46362fae23bda6ad16cdc52a85f</guid>
<pubDate>Mon, 27 Jul 2026 22:25:16 +0000</pubDate>
<title>GO-2026-6065</title>
<link>https://pkg.go.dev/vuln/GO-2026-6065</link>
<description><![CDATA[CVE-2026-55982, GHSA-mg4f-x9v4-6h2p, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">cdd0d82bcfc095d49fa065c776e7247a</guid>
<pubDate>Mon, 27 Jul 2026 22:25:09 +0000</pubDate>
<title>GO-2026-6064</title>
<link>https://pkg.go.dev/vuln/GO-2026-6064</link>
<description><![CDATA[CVE-2026-55984, GHSA-m932-crvm-gcp5, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">17d4831e0a63e0e278d394f38f0a328f</guid>
<pubDate>Mon, 27 Jul 2026 22:25:07 +0000</pubDate>
<title>GO-2026-6063</title>
<link>https://pkg.go.dev/vuln/GO-2026-6063</link>
<description><![CDATA[CVE-2026-58417, GHSA-jr5x-6h83-wrxf, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: REST API exposes organization membership of private organizations to public in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">82c9557b9de7c27332dbef363dc1ce3f</guid>
<pubDate>Mon, 27 Jul 2026 22:25:02 +0000</pubDate>
<title>GO-2026-6062</title>
<link>https://pkg.go.dev/vuln/GO-2026-6062</link>
<description><![CDATA[CVE-2026-58434, GHSA-j2w3-9c3r-g83q, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">3cd7efc69a2f13b46d55e43bc18eed38</guid>
<pubDate>Mon, 27 Jul 2026 22:24:55 +0000</pubDate>
<title>GO-2026-6061</title>
<link>https://pkg.go.dev/vuln/GO-2026-6061</link>
<description><![CDATA[GHSA-hrxh-6v49-42gf, google.golang.org/grpc, Published: Jul 27, 2026</li>
      
      
      
    </ul>

    
      <p>Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-6060">GO-2026-6060</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-58426, GHSA-hg5r-vq93-9fv6
        </li>
      
      <li class="go-textSubtle">Affects:
       
          code.gitea.io/gitea
        
      </li>
      <li class="go-textSubtle">Published: Jul 27, 2026, Unreviewed, Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">b4a5bc1980837c4297550edbaac4f547</guid>
<pubDate>Mon, 27 Jul 2026 22:24:47 +0000</pubDate>
<title>GO-2026-6059</title>
<link>https://pkg.go.dev/vuln/GO-2026-6059</link>
<description><![CDATA[CVE-2026-58431, GHSA-h56g-4qw7-2mxg, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">40468ad0038fd10fc2d2c9e53e0aad24</guid>
<pubDate>Mon, 27 Jul 2026 22:24:39 +0000</pubDate>
<title>GO-2026-6058</title>
<link>https://pkg.go.dev/vuln/GO-2026-6058</link>
<description><![CDATA[CVE-2026-58442, GHSA-h2x6-g7q6-344v, gitea.dev, Published: Jul 27, 2026, Unreviewed, Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">a414f04ecce02547fe62cbc0451826d1</guid>
<pubDate>Thu, 23 Jul 2026 04:05:58 +0000</pubDate>
<title>GO-2026-6057</title>
<link>https://pkg.go.dev/vuln/GO-2026-6057</link>
<description><![CDATA[CVE-2026-20779, GHSA-gx3v-q759-g323, code.gitea.io/gitea, Published: Jul 22, 2026, Unreviewed, Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">e8ed11c34f9d3029c0c41c389db893dc</guid>
<pubDate>Thu, 23 Jul 2026 04:05:53 +0000</pubDate>
<title>GO-2026-6056</title>
<link>https://pkg.go.dev/vuln/GO-2026-6056</link>
<description><![CDATA[CVE-2026-58422, GHSA-g9g6-qhrc-p3qc, code.gitea.io/gitea, Published: Jul 22, 2026, Unreviewed, Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">c9430b0bd53278d2d883e6ef3cd9fcbe</guid>
<pubDate>Thu, 23 Jul 2026 04:05:44 +0000</pubDate>
<title>GO-2026-6055</title>
<link>https://pkg.go.dev/vuln/GO-2026-6055</link>
<description><![CDATA[CVE-2026-58436, GHSA-fw57-jgch-pgf3, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">898627547e0554d6e0879e8fb0b47f33</guid>
<pubDate>Thu, 23 Jul 2026 04:05:39 +0000</pubDate>
<title>GO-2026-6054</title>
<link>https://pkg.go.dev/vuln/GO-2026-6054</link>
<description><![CDATA[CVE-2026-57897, GHSA-frpw-3h2q-4jj6, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">855c3b47c4535654a075e487b79dc947</guid>
<pubDate>Thu, 23 Jul 2026 04:05:35 +0000</pubDate>
<title>GO-2026-6053</title>
<link>https://pkg.go.dev/vuln/GO-2026-6053</link>
<description><![CDATA[CVE-2026-58429, GHSA-fq2p-5p22-8g6j, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">ce0289bfb40bfb0b57478124ce233f7a</guid>
<pubDate>Thu, 23 Jul 2026 04:05:29 +0000</pubDate>
<title>GO-2026-6052</title>
<link>https://pkg.go.dev/vuln/GO-2026-6052</link>
<description><![CDATA[CVE-2026-58416, GHSA-fj8v-hjwv-qm88, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">811d8c4aa2728615b1b2c4fed00adf5f</guid>
<pubDate>Thu, 23 Jul 2026 04:05:21 +0000</pubDate>
<title>GO-2026-6051</title>
<link>https://pkg.go.dev/vuln/GO-2026-6051</link>
<description><![CDATA[CVE-2026-20896, GHSA-f75j-4cw6-rmx4, code.gitea.io/gitea, Published: Jul 22, 2026, Unreviewed, Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">097281a3ea169844a9fc4bc0a257355e</guid>
<pubDate>Thu, 23 Jul 2026 04:05:16 +0000</pubDate>
<title>GO-2026-6050</title>
<link>https://pkg.go.dev/vuln/GO-2026-6050</link>
<description><![CDATA[CVE-2026-58444, GHSA-cp3q-vrj2-ghhh, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">aa335378cbed2e1cb81c43dec0fbfc2c</guid>
<pubDate>Thu, 23 Jul 2026 04:05:12 +0000</pubDate>
<title>GO-2026-6049</title>
<link>https://pkg.go.dev/vuln/GO-2026-6049</link>
<description><![CDATA[CVE-2026-59763, GHSA-9mq6-mqjj-c2c5, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">c933c1ebc8366a20477a45abd3e27485</guid>
<pubDate>Thu, 23 Jul 2026 04:05:04 +0000</pubDate>
<title>GO-2026-6048</title>
<link>https://pkg.go.dev/vuln/GO-2026-6048</link>
<description><![CDATA[CVE-2026-54481, GHSA-94v3-77j7-vm48, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">39d84607972c221ac278314762dc1399</guid>
<pubDate>Thu, 23 Jul 2026 04:04:54 +0000</pubDate>
<title>GO-2026-6047</title>
<link>https://pkg.go.dev/vuln/GO-2026-6047</link>
<description><![CDATA[CVE-2026-58437, GHSA-8p9h-49rc-qgxj, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">207f86d66f1114ab07bdb1bb0587d4e4</guid>
<pubDate>Thu, 23 Jul 2026 04:04:53 +0000</pubDate>
<title>GO-2026-6046</title>
<link>https://pkg.go.dev/vuln/GO-2026-6046</link>
<description><![CDATA[CVE-2026-58423, GHSA-7wvc-rvp7-w99x, code.gitea.io/gitea, Published: Jul 22, 2026, Unreviewed, Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">80aef442e2e9cfd6607ae138c5b7dc1a</guid>
<pubDate>Thu, 23 Jul 2026 04:04:44 +0000</pubDate>
<title>GO-2026-6045</title>
<link>https://pkg.go.dev/vuln/GO-2026-6045</link>
<description><![CDATA[CVE-2026-56443, GHSA-7p4h-3gxq-x3h3, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
+ Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">a49cc2ed4d236856c56780e30551da87</guid>
<pubDate>Thu, 23 Jul 2026 04:04:40 +0000</pubDate>
<title>GO-2026-6044</title>
<link>https://pkg.go.dev/vuln/GO-2026-6044</link>
<description><![CDATA[CVE-2026-58424, GHSA-777r-4v59-6486, code.gitea.io/gitea, Published: Jul 22, 2026, Unreviewed, Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">61ddf2f5386988ed722c88b3e534f892</guid>
<pubDate>Thu, 23 Jul 2026 04:04:31 +0000</pubDate>
<title>GO-2026-6043</title>
<link>https://pkg.go.dev/vuln/GO-2026-6043</link>
<description><![CDATA[CVE-2026-27775, GHSA-649p-mmhf-85c7, code.gitea.io/gitea, Published: Jul 22, 2026, Unreviewed, Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">c54f504a0adc9c8beaad0b7c2438a3d4</guid>
<pubDate>Thu, 23 Jul 2026 04:04:29 +0000</pubDate>
<title>GO-2026-6042</title>
<link>https://pkg.go.dev/vuln/GO-2026-6042</link>
<description><![CDATA[CVE-2026-56657, GHSA-4xjf-493q-98p3, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea SSH Key Parser Denial of Service in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">986103a01597ba15cc0036861480a7fa</guid>
<pubDate>Thu, 23 Jul 2026 04:04:19 +0000</pubDate>
<title>GO-2026-6041</title>
<link>https://pkg.go.dev/vuln/GO-2026-6041</link>
<description><![CDATA[CVE-2026-58419, GHSA-44qc-pgvp-wx7v, code.gitea.io/gitea, Published: Jul 22, 2026, Unreviewed, Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">1e8a6d5ba6fe5aa9da44046a71600733</guid>
<pubDate>Thu, 23 Jul 2026 04:04:18 +0000</pubDate>
<title>GO-2026-6040</title>
<link>https://pkg.go.dev/vuln/GO-2026-6040</link>
<description><![CDATA[CVE-2026-58511, GHSA-3r5c-2xxx-h872, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">821c23aaced9387bb10432140dea0930</guid>
<pubDate>Thu, 23 Jul 2026 04:04:12 +0000</pubDate>
<title>GO-2026-6039</title>
<link>https://pkg.go.dev/vuln/GO-2026-6039</link>
<description><![CDATA[CVE-2026-59765, GHSA-2wm4-vwp6-v7xc, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">b7dd0b7eb0d8243a7d70defed805fcb6</guid>
<pubDate>Thu, 23 Jul 2026 04:04:01 +0000</pubDate>
<title>GO-2026-6038</title>
<link>https://pkg.go.dev/vuln/GO-2026-6038</link>
<description><![CDATA[CVE-2026-58314, GHSA-2fcr-jfvc-vgg2, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: Two SSRF findings in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">ebbd2ae6a35121421d4b4a77ad68e1c4</guid>
<pubDate>Thu, 23 Jul 2026 04:04:00 +0000</pubDate>
<title>GO-2026-6037</title>
<link>https://pkg.go.dev/vuln/GO-2026-6037</link>
<description><![CDATA[CVE-2026-56755, GHSA-6hm7-3pwj-22rm, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">7e301160b2af4a7282e4b30a4a130e85</guid>
<pubDate>Thu, 23 Jul 2026 04:03:49 +0000</pubDate>
<title>GO-2026-6036</title>
<link>https://pkg.go.dev/vuln/GO-2026-6036</link>
<description><![CDATA[CVE-2026-50105, GHSA-6cqf-375w-639g, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">23bfaf7af3111baf9215a760316028ba</guid>
<pubDate>Thu, 23 Jul 2026 04:03:45 +0000</pubDate>
<title>GO-2026-6035</title>
<link>https://pkg.go.dev/vuln/GO-2026-6035</link>
<description><![CDATA[CVE-2026-57886, GHSA-6c6r-5xr4-cr5m, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">ef757c3c3a35d316b89510549dae0fb6</guid>
<pubDate>Thu, 23 Jul 2026 04:03:41 +0000</pubDate>
<title>GO-2026-6034</title>
<link>https://pkg.go.dev/vuln/GO-2026-6034</link>
<description><![CDATA[CVE-2026-56654, GHSA-683j-3ff6-hh2x, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">4cfa57e669ccc59f8bd2c888fe7adb5c</guid>
<pubDate>Thu, 23 Jul 2026 04:03:34 +0000</pubDate>
<title>GO-2026-6033</title>
<link>https://pkg.go.dev/vuln/GO-2026-6033</link>
<description><![CDATA[CVE-2026-58440, GHSA-66m4-5jjr-2rg5, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">bf9b56977d782d27debc17710ec90776</guid>
<pubDate>Thu, 23 Jul 2026 04:03:30 +0000</pubDate>
<title>GO-2026-6032</title>
<link>https://pkg.go.dev/vuln/GO-2026-6032</link>
<description><![CDATA[CVE-2026-58420, GHSA-5ggr-2f2h-jmvm, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">3407ab56b284998359adc331d7884160</guid>
<pubDate>Thu, 23 Jul 2026 04:03:19 +0000</pubDate>
<title>GO-2026-6031</title>
<link>https://pkg.go.dev/vuln/GO-2026-6031</link>
<description><![CDATA[CVE-2026-27761, GHSA-3pww-vcvm-3gmj, code.gitea.io/gitea, Published: Jul 22, 2026, Unreviewed, Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">0661704d7bb850d41b3dbc87bdc51da3</guid>
<pubDate>Thu, 23 Jul 2026 04:03:14 +0000</pubDate>
<title>GO-2026-6030</title>
<link>https://pkg.go.dev/vuln/GO-2026-6030</link>
<description><![CDATA[CVE-2026-22874, GHSA-2r5c-gw76-rh3w, code.gitea.io/gitea, Published: Jul 22, 2026, Unreviewed, Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">bb712fc9818e833bc2fa4d1e515103c0</guid>
<pubDate>Thu, 23 Jul 2026 04:03:11 +0000</pubDate>
<title>GO-2026-6029</title>
<link>https://pkg.go.dev/vuln/GO-2026-6029</link>
<description><![CDATA[CVE-2026-28740, GHSA-2m9v-5q2g-58vq, code.gitea.io/gitea, Published: Jul 22, 2026, Unreviewed, Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">00b3598c15a25b66657a5a908b7b49d6</guid>
<pubDate>Thu, 23 Jul 2026 04:03:02 +0000</pubDate>
<title>GO-2026-6028</title>
<link>https://pkg.go.dev/vuln/GO-2026-6028</link>
<description><![CDATA[CVE-2026-58428, GHSA-25gq-j9jx-43pg, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">7a8ddaf2f8a83c761c82685111c1a104</guid>
<pubDate>Thu, 23 Jul 2026 04:03:00 +0000</pubDate>
<title>GO-2026-6027</title>
<link>https://pkg.go.dev/vuln/GO-2026-6027</link>
<description><![CDATA[CVE-2026-57894, GHSA-82f7-87hm-852x, gitea.dev, Published: Jul 22, 2026, Unreviewed, Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">8d96afa8f0897f762e3de45b2e35ed2c</guid>
<pubDate>Thu, 23 Jul 2026 04:02:53 +0000</pubDate>
<title>GO-2026-6026</title>
<link>https://pkg.go.dev/vuln/GO-2026-6026</link>
<description><![CDATA[CVE-2026-62843, GHSA-83xp-526h-j3ww, github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2, Published: Jul 22, 2026, Unreviewed, File Browser: Archive builder turns backslash filenames into path traversal (zip-slip) in github.com/filebrowser/filebrowser


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">601d5f3a58486641d41f818a04c991ee</guid>
<pubDate>Thu, 23 Jul 2026 04:02:47 +0000</pubDate>
<title>GO-2026-6025</title>
<link>https://pkg.go.dev/vuln/GO-2026-6025</link>
<description><![CDATA[CVE-2026-62684, GHSA-833g-cqhp-h72j, github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2, Published: Jul 22, 2026, Unreviewed, File Browser: Share API exposes the password hash and bypass token in github.com/filebrowser/filebrowser


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">0235f48dec68aff879ac8de1084db4b0</guid>
<pubDate>Thu, 23 Jul 2026 04:02:41 +0000</pubDate>
<title>GO-2026-6024</title>
<link>https://pkg.go.dev/vuln/GO-2026-6024</link>
<description><![CDATA[CVE-2026-62685, GHSA-7rc3-g7h6-22m7, github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2, Published: Jul 22, 2026, Unreviewed, File Browser: Colliding username normalization gives two users the same home directory in github.com/filebrowser/filebrowser


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">d778ac2b32ad2b7ff636b053b9387f2a</guid>
<pubDate>Thu, 23 Jul 2026 04:02:33 +0000</pubDate>
<title>GO-2026-6023</title>
<link>https://pkg.go.dev/vuln/GO-2026-6023</link>
<description><![CDATA[CVE-2026-54562, GHSA-x756-g4x3-c64m, github.com/cloudreve/Cloudreve, github.com/cloudreve/Cloudreve/v3, and 1 more, Published: Jul 22, 2026, Unreviewed, Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses in github.com/cloudreve/Cloudreve


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">e7c8e460199a65ffbc25c80cc740529b</guid>
<pubDate>Thu, 23 Jul 2026 04:02:25 +0000</pubDate>
<title>GO-2026-6022</title>
<link>https://pkg.go.dev/vuln/GO-2026-6022</link>
<description><![CDATA[CVE-2026-54560, GHSA-vgj4-345g-jcf8, github.com/cloudreve/Cloudreve, github.com/cloudreve/Cloudreve/v3, and 1 more, Published: Jul 22, 2026, Unreviewed, Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim in github.com/cloudreve/Cloudreve


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">901c447bb35662f052cf5fa6e793ceab</guid>
<pubDate>Thu, 23 Jul 2026 04:02:20 +0000</pubDate>
<title>GO-2026-6021</title>
<link>https://pkg.go.dev/vuln/GO-2026-6021</link>
<description><![CDATA[CVE-2026-55667, GHSA-fmm7-x4gx-8jhr, github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2, Published: Jul 22, 2026, Unreviewed, File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup in github.com/filebrowser/filebrowser


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">d1721a5e433156f95ab50b61e8997046</guid>
<pubDate>Thu, 23 Jul 2026 04:02:14 +0000</pubDate>
<title>GO-2026-6020</title>
<link>https://pkg.go.dev/vuln/GO-2026-6020</link>
<description><![CDATA[CVE-2026-55668, GHSA-8wc8-hf36-mjh9, github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2, Published: Jul 22, 2026, Unreviewed, File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope in github.com/filebrowser/filebrowser


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">5dceb2da46e7b74f727cfc33ef8cecbd</guid>
<pubDate>Thu, 23 Jul 2026 04:02:08 +0000</pubDate>
<title>GO-2026-6019</title>
<link>https://pkg.go.dev/vuln/GO-2026-6019</link>
<description><![CDATA[GHSA-8qqm-fp2q-v734, github.com/zalando/skipper, Published: Jul 22, 2026, Unreviewed, Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">b870c36085280cefc3523a66edef3cf3</guid>
<pubDate>Thu, 23 Jul 2026 04:02:00 +0000</pubDate>
<title>GO-2026-6018</title>
<link>https://pkg.go.dev/vuln/GO-2026-6018</link>
<description><![CDATA[CVE-2026-54246, GHSA-5587-2x54-jj6h, github.com/zalando/skipper, Published: Jul 22, 2026, Unreviewed, Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication in github.com/zalando/skipper


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">e81ee0f2c5a4f4d2efa6412f6fcc634e</guid>
<pubDate>Thu, 23 Jul 2026 04:02:00 +0000</pubDate>
<title>GO-2026-6017</title>
<link>https://pkg.go.dev/vuln/GO-2026-6017</link>
<description><![CDATA[CVE-2026-27771, GHSA-8qw8-rq86-9pc2, code.gitea.io/gitea, Published: Jul 22, 2026, Unreviewed, Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">ae78eccb65598aaa9b06371829f321ef</guid>
<pubDate>Thu, 23 Jul 2026 04:01:49 +0000</pubDate>
<title>GO-2026-6016</title>
<link>https://pkg.go.dev/vuln/GO-2026-6016</link>
<description><![CDATA[GHSA-rjwr-m7qx-3fjr, github.com/oapi-codegen/oapi-codegen, github.com/oapi-codegen/oapi-codegen/v2, Published: Jul 22, 2026, Unreviewed, oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code in github.com/oapi-codegen/oapi-codegen


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">96688d78f66616270fca9c643049962a</guid>
<pubDate>Thu, 23 Jul 2026 04:01:46 +0000</pubDate>
<title>GO-2026-6015</title>
<link>https://pkg.go.dev/vuln/GO-2026-6015</link>
<description><![CDATA[CVE-2026-54247, GHSA-cwxq-rc9x-2jvv, github.com/zalando/skipper, Published: Jul 22, 2026, Unreviewed, Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS in github.com/zalando/skipper


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">491ea53087141693bc450859cb453166</guid>
<pubDate>Wed, 22 Jul 2026 03:01:38 +0000</pubDate>
<title>GO-2026-6014</title>
<link>https://pkg.go.dev/vuln/GO-2026-6014</link>
<description><![CDATA[CVE-2025-7453, GHSA-2hfh-94w5-wxvf, github.com/saltbo/zpan, Published: Jul 17, 2026, Unreviewed, ZPan Uses Hard-Coded Password in github.com/saltbo/zpan


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">66146219eb958696585c67b10afce1c5</guid>
<pubDate>Thu, 23 Jul 2026 04:01:36 +0000</pubDate>
<title>GO-2026-6013</title>
<link>https://pkg.go.dev/vuln/GO-2026-6013</link>
<description><![CDATA[CVE-2026-52724, GHSA-wvmp-6r4v-j6cv, github.com/kumahq/kuma, github.com/kumahq/kuma/v2, Published: Jul 22, 2026, Unreviewed, kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">a1c765aaf3c8b3b5fb059d52e64be0c0</guid>
<pubDate>Wed, 22 Jul 2026 03:01:31 +0000</pubDate>
<title>GO-2026-6012</title>
<link>https://pkg.go.dev/vuln/GO-2026-6012</link>
<description><![CDATA[CVE-2026-52832, GHSA-wpcj-rmv4-86qg, github.com/nuclio/nuclio, Published: Jul 17, 2026, Unreviewed, Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container in github.com/nuclio/nuclio.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: github.com/nuclio/nuclio before v1.16.5.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">0a1fbadb445919a7d6687747711fcea1</guid>
<pubDate>Wed, 22 Jul 2026 03:01:27 +0000</pubDate>
<title>GO-2026-6011</title>
<link>https://pkg.go.dev/vuln/GO-2026-6011</link>
<description><![CDATA[CVE-2026-53713, GHSA-wcrf-9vrr-854f, github.com/envoyproxy/gateway, Published: Jul 17, 2026, Unreviewed, Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure in github.com/envoyproxy/gateway


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">4f7d0507c710317443c1452160a727bb</guid>
<pubDate>Thu, 23 Jul 2026 04:01:32 +0000</pubDate>
<title>GO-2026-6010</title>
<link>https://pkg.go.dev/vuln/GO-2026-6010</link>
<description><![CDATA[CVE-2026-50166, GHSA-v95x-xhq5-4929, github.com/kumahq/kuma, github.com/kumahq/kuma/v2, Published: Jul 22, 2026, Unreviewed, kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">9083cc76d24bac7ca7c4f7a6262c2b34</guid>
<pubDate>Wed, 22 Jul 2026 03:01:25 +0000</pubDate>
<title>GO-2026-6009</title>
<link>https://pkg.go.dev/vuln/GO-2026-6009</link>
<description><![CDATA[CVE-2026-53719, GHSA-m2v6-2jmh-4c68, github.com/envoyproxy/gateway, Published: Jul 17, 2026, Unreviewed, Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization in github.com/envoyproxy/gateway


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">5defda5a3be76a1df4467031c9d964bb</guid>
<pubDate>Wed, 22 Jul 2026 03:01:15 +0000</pubDate>
<title>GO-2026-6008</title>
<link>https://pkg.go.dev/vuln/GO-2026-6008</link>
<description><![CDATA[CVE-2026-53717, GHSA-h7pq-86h8-rp5x, github.com/envoyproxy/gateway, Published: Jul 17, 2026, Unreviewed, Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header in github.com/envoyproxy/gateway


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">ac6c62507e2a736c4ad0a07c3c98df5f</guid>
<pubDate>Wed, 22 Jul 2026 03:01:12 +0000</pubDate>
<title>GO-2026-6007</title>
<link>https://pkg.go.dev/vuln/GO-2026-6007</link>
<description><![CDATA[CVE-2026-53718, GHSA-fcrp-7gc2-93g7, github.com/envoyproxy/gateway, Published: Jul 17, 2026, Unreviewed, Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass in github.com/envoyproxy/gateway


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">9ab5850f2752b54a6ecde05b6f30f440</guid>
<pubDate>Wed, 22 Jul 2026 03:01:02 +0000</pubDate>
<title>GO-2026-6006</title>
<link>https://pkg.go.dev/vuln/GO-2026-6006</link>
<description><![CDATA[CVE-2026-53716, GHSA-cxpq-8v7q-cg56, github.com/envoyproxy/gateway, Published: Jul 17, 2026, Unreviewed, Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit in github.com/envoyproxy/gateway


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">ecd73ad271c7ccc7e5984a50981630f5</guid>
<pubDate>Wed, 22 Jul 2026 03:00:56 +0000</pubDate>
<title>GO-2026-6005</title>
<link>https://pkg.go.dev/vuln/GO-2026-6005</link>
<description><![CDATA[CVE-2026-53715, GHSA-8fv2-88gg-hm7q, github.com/envoyproxy/gateway, Published: Jul 17, 2026, Unreviewed, Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock in github.com/envoyproxy/gateway


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">4e8c115edc771a25abdc49247a69afc5</guid>
<pubDate>Wed, 22 Jul 2026 03:00:51 +0000</pubDate>
<title>GO-2026-6004</title>
<link>https://pkg.go.dev/vuln/GO-2026-6004</link>
<description><![CDATA[CVE-2026-52833, GHSA-3v79-m2cg-89ww, github.com/nuclio/nuclio, Published: Jul 17, 2026, Unreviewed, Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE in github.com/nuclio/nuclio.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: github.com/nuclio/nuclio before v1.16.5.


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">0c6d01324a8876a8ac13dd2ccf0ea32c</guid>
<pubDate>Wed, 22 Jul 2026 03:00:45 +0000</pubDate>
<title>GO-2026-6003</title>
<link>https://pkg.go.dev/vuln/GO-2026-6003</link>
<description><![CDATA[CVE-2026-53714, GHSA-22xc-xg2r-9j7v, github.com/envoyproxy/gateway, Published: Jul 17, 2026, Unreviewed, Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode in github.com/envoyproxy/gateway


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">a9fc310e81e60cb4911dba8b16b5aba0</guid>
<pubDate>Wed, 22 Jul 2026 03:00:37 +0000</pubDate>
<title>GO-2026-6002</title>
<link>https://pkg.go.dev/vuln/GO-2026-6002</link>
<description><![CDATA[CVE-2026-58196, GHSA-pr64-jmmf-jp54, github.com/stacklok/toolhive, Published: Jul 17, 2026, Unreviewed, ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) in github.com/stacklok/toolhive


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">f2f6ea90b297b7f7844ddda8a1c19b9b</guid>
<pubDate>Mon, 27 Jul 2026 22:24:38 +0000</pubDate>
<title>GO-2026-6000</title>
<link>https://pkg.go.dev/vuln/GO-2026-6000</link>
<description><![CDATA[CVE-2026-50274, GHSA-74j5-xf3v-crq8, github.com/DataDog/dd-trace-go, github.com/DataDog/dd-trace-go/v2, Published: Jul 27, 2026</li>
      
      
      
    </ul>

    
      <p>Improper parsing of W3C baggage headers may lead to DoS in github.com/DataDog/dd-trace-go</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-5999">GO-2026-5999</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-10814, GHSA-jh6h-v6mp-h22v
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/milvus-io/milvus
        
      </li>
      <li class="go-textSubtle">Published: Jul 17, 2026, Unreviewed, milvus: RBAC grantee-id uses truncated MD5 (64-bit), enabling privilege-binding collisions and cross-role privilege forgery in github.com/milvus-io/milvus


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">c2128b5bda0b7fc22d4b00687aa8bcb1</guid>
<pubDate>Wed, 22 Jul 2026 03:00:31 +0000</pubDate>
<title>GO-2026-5998</title>
<link>https://pkg.go.dev/vuln/GO-2026-5998</link>
<description><![CDATA[CVE-2026-54495, GHSA-398h-7f66-3h4p, github.com/open-feature/open-feature-operator, Published: Jul 17, 2026, Unreviewed, open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters in github.com/open-feature/open-feature-operator


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">8015c5f536ef2e0d7bf3d31fcd63e231</guid>
<pubDate>Wed, 22 Jul 2026 03:00:23 +0000</pubDate>
<title>GO-2026-5997</title>
<link>https://pkg.go.dev/vuln/GO-2026-5997</link>
<description><![CDATA[CVE-2026-54452, GHSA-xgch-x3mx-cm3c, github.com/doyensec/safeurl, Published: Jul 17, 2026, Unreviewed, safeurl is Missing IPv6 CIDR Ranges in Blocklist in github.com/doyensec/safeurl


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">276286a5ce715b17961c7763b8d9787e</guid>
<pubDate>Wed, 22 Jul 2026 03:00:16 +0000</pubDate>
<title>GO-2026-5996</title>
<link>https://pkg.go.dev/vuln/GO-2026-5996</link>
<description><![CDATA[CVE-2026-54450, GHSA-pph6-vfjv-vpjw, github.com/stacklok/toolhive, Published: Jul 17, 2026, Unreviewed, ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway in github.com/stacklok/toolhive


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">253b03708c1f3b4afa41acc4c6588767</guid>
<pubDate>Wed, 22 Jul 2026 03:00:13 +0000</pubDate>
<title>GO-2026-5992</title>
<link>https://pkg.go.dev/vuln/GO-2026-5992</link>
<description><![CDATA[CVE-2026-61549, GHSA-qf34-295c-26v8, github.com/woodpecker-ci/woodpecker, go.woodpecker-ci.org/woodpecker, and 2 more, Published: Jul 17, 2026, Unreviewed, Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend in github.com/woodpecker-ci/woodpecker


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">92b7102758b4a435184c4ceafb86b9b7</guid>
<pubDate>Wed, 22 Jul 2026 03:00:05 +0000</pubDate>
<title>GO-2026-5991</title>
<link>https://pkg.go.dev/vuln/GO-2026-5991</link>
<description><![CDATA[CVE-2026-53603, GHSA-q4vm-pq3q-8wgq, github.com/forgekeep/nebula-mesh, Published: Jul 17, 2026, Unreviewed, nebula-mesh: Operator session tokens stored in plaintext in the database in github.com/forgekeep/nebula-mesh


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">f66e2582fddde0984a7d51d24bd7f3b7</guid>
<pubDate>Wed, 22 Jul 2026 02:59:56 +0000</pubDate>
<title>GO-2026-5990</title>
<link>https://pkg.go.dev/vuln/GO-2026-5990</link>
<description><![CDATA[CVE-2026-54629, GHSA-mf78-3rpf-r784, github.com/julien040/anyquery, Published: Jul 17, 2026, Unreviewed, Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode in github.com/julien040/anyquery


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">6ccc9d62f9964649e4a0fbfd4c7d01c6</guid>
<pubDate>Thu, 23 Jul 2026 20:36:11 +0000</pubDate>
<title>GO-2026-5989</title>
<link>https://pkg.go.dev/vuln/GO-2026-5989</link>
<description><![CDATA[CVE-2026-55512, GHSA-m3cx-mwpg-32jg, github.com/forgekeep/nebula-mesh, github.com/juev/nebula-mesh, Published: Jul 23, 2026</li>
      
      
      
    </ul>

    
      <p>When OIDC is enabled, the login endpoint is reachable without authentication and is registered outside the rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map.

An unauthenticated remote client can grow the state storage, bounded by request throughput rather than by configured auth rate limits, potentially leading to a denial of service.</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-5988">GO-2026-5988</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-54628, GHSA-hwrq-8wxh-q4xv
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/julien040/anyquery
        
      </li>
      <li class="go-textSubtle">Published: Jul 17, 2026, Unreviewed, Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode in github.com/julien040/anyquery


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">a38fa753a950fb02afe1e025cb910909</guid>
<pubDate>Thu, 23 Jul 2026 20:36:06 +0000</pubDate>
<title>GO-2026-5987</title>
<link>https://pkg.go.dev/vuln/GO-2026-5987</link>
<description><![CDATA[CVE-2026-55513, GHSA-g4x6-jcvr-9m3g, github.com/forgekeep/nebula-mesh, github.com/juev/nebula-mesh, Published: Jul 23, 2026</li>
      
      
      
    </ul>

    
      <p>The nebula-mesh Web UI host creation ignores the configured enrollment token TTL and instead mints 24-hour bearer enrollment tokens. This can lead to tokens remaining valid for longer than intended, increasing the window of opportunity for an attacker to use an intercepted token.</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-5986">GO-2026-5986</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          CVE-2026-61699, GHSA-cm26-5974-52h8
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/forgekeep/nebula-mesh
        
      </li>
      <li class="go-textSubtle">Published: Jul 17, 2026, Unreviewed, nebula-mesh: Certificate revocation is never enforced at the mesh in github.com/forgekeep/nebula-mesh


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">b722e27e672a6b46526f2faf3052f9e0</guid>
<pubDate>Wed, 22 Jul 2026 02:59:40 +0000</pubDate>
<title>GO-2026-5985</title>
<link>https://pkg.go.dev/vuln/GO-2026-5985</link>
<description><![CDATA[GHSA-7rx3-5wx3-5v76, github.com/forgekeep/nebula-mesh, Published: Jul 17, 2026, Unreviewed, Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">21f73b5299edf6438cde16012e498f55</guid>
<pubDate>Wed, 22 Jul 2026 02:59:35 +0000</pubDate>
<title>GO-2026-5984</title>
<link>https://pkg.go.dev/vuln/GO-2026-5984</link>
<description><![CDATA[CVE-2026-53604, GHSA-2p2f-px33-4vv5, github.com/forgekeep/nebula-mesh, Published: Jul 17, 2026, Unreviewed, nebula-mesh: CA private key not zeroized on web mobile-bundle error paths in github.com/forgekeep/nebula-mesh


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">bda3fbc21695aa15dd605560c3a640c3</guid>
<pubDate>Mon, 27 Jul 2026 22:24:30 +0000</pubDate>
<title>GO-2026-5983</title>
<link>https://pkg.go.dev/vuln/GO-2026-5983</link>
<description><![CDATA[CVE-2026-54448, GHSA-q3fv-x8vg-qqm4, github.com/aquasecurity/trivy, Published: Jul 27, 2026</li>
      
      
      
    </ul>

    
      <p>Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser in github.com/aquasecurity/trivy</p>
    
  </div>

      </div>
    
      <div class="VulnList-header">
        <h2 class="VulnList-title" >
          <a href="https://pkg.go.dev/vuln/GO-2026-5982">GO-2026-5982</a>
        </h2>
        
  
  

      </div>
      <div class="VulnList-details">
        
  
  <div class="Vuln-details">
    
    <ul class="Vuln-detailsMetadata">
      
        <li class="go-textSubtle Vuln-alias">
          GHSA-pqg7-v6wh-3pfp
        </li>
      
      <li class="go-textSubtle">Affects:
       
          github.com/almeidapaulopt/tsdproxy
        
      </li>
      <li class="go-textSubtle">Published: Jul 17, 2026, Unreviewed, TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">39e0cff525128f2ffcc01b2e707d1ab8</guid>
<pubDate>Wed, 22 Jul 2026 02:59:23 +0000</pubDate>
<title>GO-2026-5981</title>
<link>https://pkg.go.dev/vuln/GO-2026-5981</link>
<description><![CDATA[GHSA-mqxv-9rm6-w8qc, github.com/lin-snow/ech0, Published: Jul 17, 2026, Unreviewed, Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware in github.com/lin-snow/ech0


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">e324f6d42b068341548c1688939a1f87</guid>
<pubDate>Wed, 22 Jul 2026 02:59:19 +0000</pubDate>
<title>GO-2026-5980</title>
<link>https://pkg.go.dev/vuln/GO-2026-5980</link>
<description><![CDATA[CVE-2026-50158, GHSA-2c7f-fxww-6w6c, github.com/eat-pray-ai/yutu, Published: Jul 17, 2026, Unreviewed, yutu: Arbitrary File Write via MCP `caption-download` Tool in github.com/eat-pray-ai/yutu


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">b54ab565b540b8905bce7ae333b92bc1</guid>
<pubDate>Wed, 22 Jul 2026 02:59:12 +0000</pubDate>
<title>GO-2026-5979</title>
<link>https://pkg.go.dev/vuln/GO-2026-5979</link>
<description><![CDATA[CVE-2026-50006, GHSA-xrcf-6jh3-ggvx, github.com/julien040/anyquery, Published: Jul 17, 2026, Unreviewed, Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode in github.com/julien040/anyquery


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>
<item>




<guid isPermaLink="false">465a329666816739c2217cf5fd1618ae</guid>
<pubDate>Wed, 22 Jul 2026 02:59:05 +0000</pubDate>
<title>GO-2026-5978</title>
<link>https://pkg.go.dev/vuln/GO-2026-5978</link>
<description><![CDATA[CVE-2026-50125, GHSA-qw5r-ppcg-f8rj, github.com/StacklokLabs/mkp, Published: Jul 17, 2026, Unreviewed, MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion in github.com/StacklokLabs/mkp


    <br/>



    


    <p><sub><i>-- Delivered by <a href="https://rsseverything.com">RssEverything</a> service</i></sub></p>


]]></description>
</item>

  </channel>
</rss>

