CVEs we hold for Git
Records whose assigning authority named Git as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9312Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path…GitHub Enterprise Server
CVE-2026-9132Missing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via…GitHub Enterprise Server
CVE-2026-9106UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via…GitHub Enterprise Server
CVE-2026-90712Gitlawb openclaude xAI OAuth Callback xaiOAuthCallback.ts waitForCallback denial of serviceGitlawb openclaude
CVE-2026-88765Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLabGitLab
CVE-2026-87818GitPython 3.1.59 Local File Content Oracle via --no-indexgitpython-developers GitPython
CVE-2026-87817GitPython before 3.1.60 Remote Code Execution via Git Directory Impersonationgitpython-developers GitPython
CVE-2026-8606Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL EndpointGitHub Enterprise Server
CVE-2026-8589Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabGitLab
CVE-2026-85706Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabGitLab
CVE-2026-82253gitoxide before 0.82.0 Path Traversal via Submodule Name Validation BypassGitoxideLabs gitoxide
CVE-2026-82252gitoxide before 0.52.1 Repository Boundary Violation via symlinked .gitmodulesGitoxideLabs gitoxide
CVE-2026-82249gitoxide before 0.38.2 Credential Helper Protocol Field InjectionGitoxideLabs gitoxide
CVE-2026-82247gitoxide before 0.37.1 HTTP Basic credential leak via URL parsingGitoxideLabs gitoxide
CVE-2026-8106Reflected HTML injection vulnerability in GitHub Enterprise Server Management Console login page allowed credential…GitHub Enterprise Server
CVE-2026-8034Server-side request forgery vulnerability in GitHub Enterprise Server notebook viewer via URL parser confusionGitHub Enterprise Server
CVE-2026-78679GitPython before 3.1.59 Arbitrary File Read via TagReference.creategitpython-developers GitPython
CVE-2026-78678GitPython before 3.1.59 Arbitrary File Read via Repo.blame()gitpython-developers GitPython
CVE-2026-78677GitPython before 3.1.59 Path Traversal via separate-git-dirgitpython-developers GitPython
CVE-2026-78676GitPython before 3.1.59 Remote Code Execution via Config Injectiongitpython-developers GitPython
CVE-2026-78675GitPython before 3.1.59 Local File Content Disclosure via .gitmodulesgitpython-developers GitPython
CVE-2026-78252Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabGitLab
CVE-2026-76851Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access…GitHub Enterprise Server
CVE-2026-76222GitPython before 3.1.58 Path Traversal via .gitmodules Submodule Namegitpython-developers GitPython
CVE-2026-76221GitPython before 3.1.58 Config Injection via option-namegitpython-developers GitPython
CVE-2026-76220GitPython before 3.1.58 Command Execution via split_single_char_optionsgitpython-developers GitPython
CVE-2026-76219GitPython before 3.1.58 Arbitrary File Overwrite via read-treegitpython-developers GitPython
CVE-2026-76218GitPython before 3.1.58 Remote Code Execution via Repo.initgitpython-developers GitPython
CVE-2026-76217GitPython before 3.1.58 Arbitrary File Read via pathspec-from-filegitpython-developers GitPython
CVE-2026-7541Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via unauthenticated API endpointGitHub Enterprise Server
CVE-2026-7481Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabGitLab
CVE-2026-7377Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabGitLab
CVE-2026-73625GitPython before 3.1.54 Remote Code Execution via kwarg value smugglinggitpython-developers GitPython
CVE-2026-73624GitPython before 3.1.54 Arbitrary File Overwrite via diffgitpython-developers GitPython
CVE-2026-73623GitPython before 3.1.54 Remote Code Execution via --templategitpython-developers GitPython
CVE-2026-73622GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add()gitpython-developers GitPython
CVE-2026-73621GitPython before 3.1.56 Arbitrary File Truncation via Commit.countgitpython-developers GitPython
CVE-2026-73620GitPython before 3.1.57 Arbitrary File Overwrite and Readgitpython-developers GitPython
CVE-2026-73619GitPython before 3.1.57 Arbitrary File Read via Repo.archive()gitpython-developers GitPython
CVE-2026-69097GitPython before 3.1.53 Config Injection via Submodule Namesgitpython-developers GitPython
CVE-2026-6896Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabGitLab
CVE-2026-6736Authentication bypass vulnerability in GitHub Enterprise Server allowed creation of local user accounts bypassing the…GitHub Enterprise Server
CVE-2026-67326GitPython before 3.1.50 Newline Injection via config_writer sectiongitpython-developers GitPython
CVE-2026-67325GitPython before 3.1.51 Command Injection via option prefix abbreviationgitpython-developers GitPython
CVE-2026-67324GitPython 3.1.50 Authentication Bypass via Joined Short Optionsgitpython-developers GitPython
CVE-2026-67323GitPython before 3.1.51 Command Injection via unguarded Git optionsgitpython-developers GitPython
CVE-2026-67322GitPython before 3.1.52 Environment Variable Exfiltration via clone_fromgitpython-developers GitPython
CVE-2026-63728Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Featuregitleaks
CVE-2026-6335Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabGitLab
CVE-2026-62960Git for Windows: Server-advertised bundle-uri can trigger outbound SMB callbacks via UNC and file:// paths on Windowsgit-for-windows git
CVE-2026-6073Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabGitLab
CVE-2026-59765SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud MetadataGitea Open Source Git Server
CVE-2026-59763Unbounded Arch package file metadata can cause resource amplification in Gitea package uploadsGitea Open Source Git Server
CVE-2026-5921Server-Side Request Forgery in GitHub Enterprise Server allowed extraction of sensitive environment variables via…GitHub Enterprise Server
CVE-2026-58511Webhook Authorization Header Returned in Plaintext via APIGitea Open Source Git Server
CVE-2026-58510GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on…Gitea Open Source Git Server
CVE-2026-58508Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)Gitea Open Source Git Server
CVE-2026-58507Private Repository Existence Disclosure via go-get Meta EndpointGitea Open Source Git Server
CVE-2026-5845Improper authorization fallback allows scoped user-to-server token installation escape in GitHub Enterprise ServerGitHub Enterprise Server
CVE-2026-58445Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel APIGitea Open Source Git Server
CVE-2026-58444Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private…Gitea Open Source Git Server
CVE-2026-58443Public-only repository tokens can update private PR head branchesGitea Open Source Git Server
CVE-2026-58442Repository migration SSRF via multi-answer DNS allow-list bypassGitea Open Source Git Server
CVE-2026-58441SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURLGitea Open Source Git Server
CVE-2026-58440Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of…Gitea Open Source Git Server
CVE-2026-58439Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval FlagGitea Open Source Git Server
CVE-2026-58438Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot…Gitea Open Source Git Server
CVE-2026-58436ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requestsGitea Open Source Git Server
CVE-2026-58434Private Repository Metadata Remains Accessible After Access RevocationGitea Open Source Git Server
CVE-2026-58433Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization settingGitea Open Source Git Server
CVE-2026-58432Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for…Gitea Open Source Git Server
CVE-2026-58431Public-only API token restriction is not enforced on team API routesGitea Open Source Git Server
CVE-2026-58429Public-Only Personal access tokens scope bypass in Organization and Permission EndpointsGitea Open Source Git Server
CVE-2026-58428Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)Gitea Open Source Git Server
CVE-2026-58427Private org member list leaked via /members API endpoint — incomplete fix for PR #38145Gitea Open Source Git Server
CVE-2026-58426Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state…Gitea Open Source Git Server
CVE-2026-58425OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)Gitea Open Source Git Server
CVE-2026-58423LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositoriesGitea Open Source Git Server
CVE-2026-58422Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accountsGitea Open Source Git Server
CVE-2026-58421Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of serviceGitea Open Source Git Server
CVE-2026-58419Notification API leaks private issue metadata after access revocationGitea Open Source Git Server
CVE-2026-58417REST API exposes organization membership of private organizations to publicGitea Open Source Git Server
CVE-2026-58416Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)Gitea Open Source Git Server
CVE-2026-58053Gitea act_runner - Container Hardening Bypass via Workflow Container OptionsGitea act_runner
CVE-2026-57897Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIsGitea Open Source Git Server
CVE-2026-57894Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository…Gitea Open Source Git Server
CVE-2026-57886Cross-repository issue/comment attachment re-linking can expose private attachment contentGitea Open Source Git Server
CVE-2026-56755Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package UploadGitea Open Source Git Server
CVE-2026-56750Gitea Remember-Me Token Theft Not Invalidating Attacker SessionGitea Open Source Git Server
CVE-2026-56654Privilege Escalation via Access Token Scope Escalation in APIGitea Open Source Git Server
CVE-2026-56443Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after…Gitea Open Source Git Server
CVE-2026-55987OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix…Gitea Open Source Git Server
CVE-2026-55986Email Management API Bypasses ManageCredentials Feature RestrictionsGitea Open Source Git Server
CVE-2026-55984Null Pointer Dereference in AddTime API Causes Authenticated Denial of ServiceGitea Open Source Git Server
CVE-2026-55982OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token ScopesGitea Open Source Git Server
CVE-2026-5512Improper authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository names via…GitHub Enterprise Server
CVE-2026-54481Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)Gitea Open Source Git Server
CVE-2026-54163secure_headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted inputgithub secure_headers
CVE-2026-5262Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabGitLab
CVE-2026-50105RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)Gitea Open Source Git Server
CVE-2026-48799Postiz: Unauthenticated arbitrary lifetime PRO grant via Nowpayments webhookgitroomhq postiz-app
CVE-2026-48783Postiz has an unauthenticated billing-enforcement bypass via /public/modify-subscriptiongitroomhq postiz-app
CVE-2026-48781Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgerygitroomhq postiz-app
CVE-2026-48529GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusiongithub-mcp-server
CVE-2026-47427GitHub MCP Server: Nil Pointer Dereference DoS in completion/complete Handlergithub-mcp-server
CVE-2026-45261GitButler: Link injection via forge integration enables arbitrary script executiongitbutlerapp gitbutler
CVE-2026-45033GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitorgithub copilot-cli
CVE-2026-44471gitoxide: Symlink prefix-reuse allows worktree escape during checkoutGitoxideLabs gitoxide
CVE-2026-44244GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPathgitpython-developers GitPython
CVE-2026-44243GitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repositorygitpython-developers GitPython
CVE-2026-4332Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabGitLab
CVE-2026-4296Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via…GitHub Enterprise Server
CVE-2026-42931Denial of Service via Unbounded io.ReadAll in NPM Package Tag EndpointGitea Open Source Git Server
CVE-2026-42346Postiz: TOCTOU DNS rebinding bypasses all SSRF URL validation pathsgitroomhq postiz-app
CVE-2026-42298Postiz: Arbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.devgitroomhq postiz-app
CVE-2026-42284GitPython: Unsafe option check validates multi_options before shlex.split transforms itgitpython-developers GitPython
CVE-2026-42074OpenClaude: Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` InputGitlawb openclaude
CVE-2026-42073OpenClaude's MCP OAuth Callback: State Check Bypass via error Param Leads to DoSGitlawb openclaude
CVE-2026-40487Postiz Has Unrestricted File Upload via MIME Type Spoofing that Leads to Stored XSSgitroomhq postiz-app
CVE-2026-40168Postiz has Server-Side Request Forgery via Redirect Bypass in /api/public/streamgitroomhq postiz-app
CVE-2026-40034gitoxide - Command Injection via Partial .gitmodules Override in gix-submodulegitoxide; gitoxide gix-submodule; gitoxide gix
CVE-2026-3854Remote code execution via git push option injection in GitHub Enterprise ServerGitHub Enterprise Server
CVE-2026-3582Incorrect Authorization in GitHub Enterprise Server allows access to issue and commit search results without repo scopeGitHub Enterprise Server
CVE-2026-35570OpenClaude has Sandbox Bypass via Early-Exit Logic Flaw that Allows Path TraversalGitlawb openclaude
CVE-2026-34590Postiz: SSRF via Webhook Creation Endpoint Missing URL Safety Validationgitroomhq postiz-app
200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.