Go Vulnerability Database
Data about new vulnerabilities come directly from Go package maintainers or sources such as MITRE and GitHub. Reports are curated by the Go Security team. Learn more at go.dev/security/vuln.
Search
Recent Reports
GO-2026-6057
- CVE-2026-20779, GHSA-gx3v-q759-g323
- Affects: code.gitea.io/gitea
- Published: Jul 22, 2026
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
GO-2026-6056
- CVE-2026-58422, GHSA-g9g6-qhrc-p3qc
- Affects: code.gitea.io/gitea
- Published: Jul 22, 2026
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
GO-2026-6055
- CVE-2026-58436, GHSA-fw57-jgch-pgf3
- Affects: gitea.dev
- Published: Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev
GO-2026-6054
- CVE-2026-57897, GHSA-frpw-3h2q-4jj6
- Affects: gitea.dev
- Published: Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev
GO-2026-6053
- CVE-2026-58429, GHSA-fq2p-5p22-8g6j
- Affects: gitea.dev
- Published: Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev
If you don't see an existing, public Go vulnerability in a publicly importable package in our database, please let us know.