Last scanned:
This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could exploit stored XSS to hijack admin sessions, or leverage HTTP/2 CONTINUATION frame flooding to crash the service, while other library flaws could enable SSRF or memory corruption. These vulnerabilities are reachable without special configuration, so this image is unsuitable for deployment until all critical and high-severity findings are fixed.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2024-6886 | CRITICAL10 | code.gitea.io/gitea 1.20.6 fixed in 1.22.1 | 33.0% High Exploitation Risk | Directly ExposedContext importance: HIGH |
| CVE-2023-45288 | CRITICAL9.75 | golang.org/x/net v0.13.0 fixed in 0.23.0 | 92.0% Actively Exploited | Directly ExposedContext importance: HIGH |
| CVE-2023-45288 | CRITICAL9.75 | stdlib v1.20.11 fixed in 1.21.9, 1.22.2 | 92.0% Actively Exploited | Directly ExposedContext importance: HIGH |
| CVE-2024-24790 | HIGH7.84 | stdlib v1.20.11 fixed in 1.21.11, 1.22.4 | 2.0% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2024-0553 | HIGH7.5 | gnutls 3.8.0-r2 fixed in 3.8.3-r0 | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2024-0567 | HIGH7.5 | gnutls 3.8.0-r2 fixed in 3.8.3-r0 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2023-5363 | HIGH7.5 | libcrypto3 3.1.3-r0 fixed in 3.1.4-r0 | 3.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-28757 | HIGH7.5 | libexpat 2.5.0-r1 fixed in 2.6.2-r0 | 2.0% Low-Moderate Risk | Directly Exposed |
| CVE-2024-45490 | HIGH7.5 | libexpat 2.5.0-r1 fixed in 2.6.3-r0 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2024-8176 | HIGH7.5 | libexpat 2.5.0-r1 fixed in 2.7.0-r0 | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2023-5363 | HIGH7.5 | libssl3 3.1.3-r0 fixed in 3.1.4-r0 | 3.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-25062 | HIGH7.5 | libxml2 2.11.6-r0 fixed in 2.11.7-r0 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2025-27113 | HIGH7.5 | libxml2 2.11.6-r0 fixed in 2.11.8-r2 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-32952 | HIGH7.5 | github.com/Azure/go-ntlmssp v0.0.0-20221128193559-754e69321358 fixed in 0.1.1 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2023-39325 | HIGH7.5 | golang.org/x/net v0.13.0 fixed in 0.17.0 | 3.8% Low-Moderate Risk | Directly ExposedContext importance: HIGH |
| CVE-2024-34156 | HIGH7.5 | stdlib v1.20.11 fixed in 1.22.7, 1.23.1 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2025-61726 | HIGH7.5 | stdlib v1.20.11 fixed in 1.24.12, 1.25.6 | 1.9% Low-Moderate Risk | Directly Exposed |
| CVE-2026-39828 | HIGH7.48 | golang.org/x/crypto v0.11.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-39832 | HIGH7.39 | golang.org/x/crypto v0.11.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2023-7104 | HIGH7.3 | sqlite-libs 3.41.2-r2 fixed in 3.41.2-r3 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-39821 | MEDIUM6.97 | golang.org/x/net v0.13.0 fixed in 0.55.0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-44973 | MEDIUM6.88 | github.com/go-git/go-billy/v5 v5.4.1 fixed in 5.9.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-3445 | MEDIUM6.88 | github.com/mholt/archiver/v3 v3.5.1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-39831 | MEDIUM6.88 | golang.org/x/crypto v0.11.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-25681 | MEDIUM6.88 | golang.org/x/net v0.13.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27136 | MEDIUM6.88 | golang.org/x/net v0.13.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-0406 | MEDIUM6.63 | github.com/mholt/archiver/v3 v3.5.1 No fix yet | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-39822 | MEDIUM6.63 | stdlib v1.20.11 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-45337 | MEDIUM6.56 | golang.org/x/crypto v0.11.0 fixed in 0.31.0 | 3.2% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2025-24928 | MEDIUM6.54 | libxml2 2.11.6-r0 fixed in 2.11.8-r1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-6129 | MEDIUM6.5 | libcrypto3 3.1.3-r0 fixed in 3.1.4-r3 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2023-6129 | MEDIUM6.5 | libssl3 3.1.3-r0 fixed in 3.1.4-r3 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-32414 | MEDIUM6.38 | libxml2 2.11.6-r0 fixed in 2.11.8-r3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-32415 | MEDIUM6.38 | libxml2 2.11.6-r0 fixed in 2.11.8-r3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-31115 | MEDIUM6.38 | xz-libs 5.4.3-r0 fixed in 5.4.3-r1 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-20736 | MEDIUM6.38 | code.gitea.io/gitea 1.20.6 fixed in 1.25.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-44740 | MEDIUM6.38 | github.com/go-git/go-billy/v5 v5.4.1 fixed in 5.9.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-49568 | MEDIUM6.38 | github.com/go-git/go-git/v5 v5.6.1 fixed in 5.11.0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-21614 | MEDIUM6.38 | github.com/go-git/go-git/v5 v5.6.1 fixed in 5.13.0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-45022 | MEDIUM6.38 | github.com/go-git/go-git/v5 v5.6.1 fixed in 5.19.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-30204 | MEDIUM6.38 | github.com/golang-jwt/jwt/v4 v4.5.0 fixed in 4.5.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-65637 | MEDIUM6.38 | github.com/sirupsen/logrus v1.9.0 fixed in 1.8.3, 1.9.1, 1.9.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-22869 | MEDIUM6.38 | golang.org/x/crypto v0.11.0 fixed in 0.35.0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-47913 | MEDIUM6.38 | golang.org/x/crypto v0.11.0 fixed in 0.43.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-39829 | MEDIUM6.38 | golang.org/x/crypto v0.11.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-39830 | MEDIUM6.38 | golang.org/x/crypto v0.11.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-39835 | MEDIUM6.38 | golang.org/x/crypto v0.11.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-46597 | MEDIUM6.38 | golang.org/x/crypto v0.11.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-45338 | MEDIUM6.38 | golang.org/x/net v0.13.0 fixed in 0.33.0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-33814 | MEDIUM6.38 | golang.org/x/net v0.13.0 fixed in 0.53.0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-22868 | MEDIUM6.38 | golang.org/x/oauth2 v0.8.0 fixed in 0.27.0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-61729 | MEDIUM6.38 | stdlib v1.20.11 fixed in 1.24.11, 1.25.5 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-25679 | MEDIUM6.38 | stdlib v1.20.11 fixed in 1.25.8, 1.26.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-27145 | MEDIUM6.38 | stdlib v1.20.11 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-32280 | MEDIUM6.38 | stdlib v1.20.11 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-32281 | MEDIUM6.38 | stdlib v1.20.11 fixed in 1.25.9, 1.26.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-32283 | MEDIUM6.38 | stdlib v1.20.11 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-33811 | MEDIUM6.38 | stdlib v1.20.11 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-33814 | MEDIUM6.38 | stdlib v1.20.11 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-39820 | MEDIUM6.38 | stdlib v1.20.11 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-39836 | MEDIUM6.38 | stdlib v1.20.11 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42499 | MEDIUM6.38 | stdlib v1.20.11 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-42504 | MEDIUM6.38 | stdlib v1.20.11 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-58183 | MEDIUM6.38 | stdlib v1.20.11 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-61728 | MEDIUM6.38 | stdlib v1.20.11 fixed in 1.24.12, 1.25.6 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-41506 | MEDIUM6.29 | github.com/go-git/go-git/v5 v5.6.1 fixed in 5.18.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42508 | MEDIUM6.29 | golang.org/x/crypto v0.11.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2023-48795 | MEDIUM6.14 | golang.org/x/crypto v0.11.0 fixed in 0.17.0 | 93.3% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2026-46595 | MEDIUM6.03 | golang.org/x/crypto v0.11.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-26519 | MEDIUM5.95 | musl 1.2.4-r1 fixed in 1.2.4-r3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-47907 | MEDIUM5.95 | stdlib v1.20.11 fixed in 1.23.12, 1.24.6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-5981 | MEDIUM5.9 | gnutls 3.8.0-r2 fixed in 3.8.3-r0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2023-6237 | MEDIUM5.9 | libcrypto3 3.1.3-r0 fixed in 3.1.4-r4 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-5535 | MEDIUM5.9 | libcrypto3 3.1.3-r0 fixed in 3.1.6-r0 | 5.6% Low-Moderate Risk | Directly Exposed |
| CVE-2024-50602 | MEDIUM5.9 | libexpat 2.5.0-r1 fixed in 2.6.4-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2023-6237 | MEDIUM5.9 | libssl3 3.1.3-r0 fixed in 3.1.4-r4 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-5535 | MEDIUM5.9 | libssl3 3.1.3-r0 fixed in 3.1.6-r0 | 5.6% Low-Moderate Risk | Directly Exposed |
| CVE-2024-24786 | MEDIUM5.9 | google.golang.org/protobuf v1.30.0 fixed in 1.33.0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-24791 | MEDIUM5.9 | stdlib v1.20.11 fixed in 1.21.12, 1.22.5 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2024-34158 | MEDIUM5.9 | stdlib v1.20.11 fixed in 1.22.7, 1.23.1 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-4673 | MEDIUM5.78 | stdlib v1.20.11 fixed in 1.23.10, 1.24.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-4741 | MEDIUM5.6 | libcrypto3 3.1.3-r0 fixed in 3.1.6-r0 | 2.9% Low-Moderate Risk | Directly Exposed |
| CVE-2024-4741 | MEDIUM5.6 | libssl3 3.1.3-r0 fixed in 3.1.6-r0 | 2.9% Low-Moderate Risk | Directly Exposed |
| CVE-2025-11579 | MEDIUM5.52 | github.com/nwaples/rardecode v1.1.3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39827 | MEDIUM5.52 | golang.org/x/crypto v0.11.0 fixed in 0.52.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39834 | MEDIUM5.52 | golang.org/x/crypto v0.11.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2023-29407 | MEDIUM5.52 | golang.org/x/image v0.7.0 fixed in 0.10.0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2023-29408 | MEDIUM5.52 | golang.org/x/image v0.7.0 fixed in 0.10.0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-33809 | MEDIUM5.52 | golang.org/x/image v0.7.0 fixed in 0.38.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-33813 | MEDIUM5.52 | golang.org/x/image v0.7.0 fixed in 0.42.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-46599 | MEDIUM5.52 | golang.org/x/image v0.7.0 fixed in 0.41.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-46601 | MEDIUM5.52 | golang.org/x/image v0.7.0 fixed in 0.43.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-22872 | MEDIUM5.52 | golang.org/x/net v0.13.0 fixed in 0.38.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-25680 | MEDIUM5.52 | golang.org/x/net v0.13.0 fixed in 0.55.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-24785 | MEDIUM5.52 | stdlib v1.20.11 fixed in 1.21.8, 1.22.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-47906 | MEDIUM5.52 | stdlib v1.20.11 fixed in 1.23.12, 1.24.6 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-61727 | MEDIUM5.52 | stdlib v1.20.11 fixed in 1.24.11, 1.25.5 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39825 | MEDIUM5.52 | stdlib v1.20.11 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-0727 | MEDIUM5.5 | libcrypto3 3.1.3-r0 fixed in 3.1.4-r5 | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-0727 | MEDIUM5.5 | libssl3 3.1.3-r0 fixed in 3.1.4-r5 | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-34459 | MEDIUM5.5 | libxml2 2.11.6-r0 fixed in 2.11.8-r0 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-32282 | MEDIUM5.44 | stdlib v1.20.11 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-24784 | MEDIUM5.4 | stdlib v1.20.11 fixed in 1.21.8, 1.22.1 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2023-5678 | MEDIUM5.3 | libcrypto3 3.1.3-r0 fixed in 3.1.4-r1 | 4.5% Low-Moderate Risk | Directly Exposed |
| CVE-2024-4603 | MEDIUM5.3 | libcrypto3 3.1.3-r0 fixed in 3.1.5-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-5678 | MEDIUM5.3 | libssl3 3.1.3-r0 fixed in 3.1.4-r1 | 4.5% Low-Moderate Risk | Directly Exposed |
| CVE-2024-4603 | MEDIUM5.3 | libssl3 3.1.3-r0 fixed in 3.1.5-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-12133 | MEDIUM5.3 | libtasn1 4.19.0-r1 fixed in 4.20.0-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-39326 | MEDIUM5.3 | stdlib v1.20.11 fixed in 1.20.12, 1.21.5 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2023-45289 | MEDIUM5.3 | stdlib v1.20.11 fixed in 1.21.8, 1.22.1 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-45290 | MEDIUM5.3 | stdlib v1.20.11 fixed in 1.21.8, 1.22.1 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33812 | MEDIUM5.18 | golang.org/x/image v0.7.0 fixed in 0.39.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-42502 | MEDIUM5.18 | golang.org/x/net v0.13.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32289 | MEDIUM5.18 | stdlib v1.20.11 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-68121 | MEDIUM5.1 | stdlib v1.20.11 fixed in 1.24.13, 1.25.7, 1.26.0-rc.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-24783 | MEDIUM5.02 | stdlib v1.20.11 fixed in 1.21.8, 1.22.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2024-34155 | MEDIUM5.02 | stdlib v1.20.11 fixed in 1.22.7, 1.23.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-45336 | MEDIUM5.02 | stdlib v1.20.11 fixed in 1.22.11, 1.23.5, 1.24.0-rc.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2024-32002 | MEDIUM4.97 | git 2.40.1-r0 fixed in 2.40.3-r0 | 25.3% High Exploitation Risk | Post-ExploitContext importance: MEDIUM |
| CVE-2024-2511 | MEDIUM4.81 | libcrypto3 3.1.3-r0 fixed in 3.1.4-r6 | 54.0% Actively Exploited | Directly Exposed |
| CVE-2024-2511 | MEDIUM4.81 | libssl3 3.1.3-r0 fixed in 3.1.4-r6 | 54.0% Actively Exploited | Directly Exposed |
| CVE-2023-49569 | MEDIUM4.7 | github.com/go-git/go-git/v5 v5.6.1 fixed in 5.11.0 | 1.5% Low-Moderate Risk | Post-ExploitContext importance: MEDIUM |
| CVE-2023-52426 | MEDIUM4.67 | libexpat 2.5.0-r1 fixed in 2.6.0-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2022-31022 | MEDIUM4.67 | github.com/blevesearch/bleve/v2 v2.3.7 fixed in 2.5.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-6104 | MEDIUM4.67 | github.com/hashicorp/go-retryablehttp v0.7.2 fixed in 0.7.7 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-39833 | MEDIUM4.67 | golang.org/x/crypto v0.11.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-24789 | MEDIUM4.67 | stdlib v1.20.11 fixed in 1.21.11, 1.22.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-32288 | MEDIUM4.67 | stdlib v1.20.11 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-68942 | MEDIUM4.59 | code.gitea.io/gitea 1.20.6 fixed in 1.22.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-45571 | MEDIUM4.59 | github.com/go-git/go-git/v5 v5.6.1 fixed in 5.19.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42506 | MEDIUM4.59 | golang.org/x/net v0.13.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-22871 | MEDIUM4.59 | stdlib v1.20.11 fixed in 1.23.8, 1.24.2 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-27142 | MEDIUM4.59 | stdlib v1.20.11 fixed in 1.25.8, 1.26.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39823 | MEDIUM4.59 | stdlib v1.20.11 fixed in 1.25.10, 1.26.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39826 | MEDIUM4.59 | stdlib v1.20.11 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-28834 | MEDIUM4.5 | gnutls 3.8.0-r2 fixed in 3.8.4-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-68939 | MEDIUM4.5 | code.gitea.io/gitea 1.20.6 fixed in 1.23.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-68938 | MEDIUM4.5 | code.gitea.io/gitea 1.20.6 fixed in 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-68941 | MEDIUM4.5 | code.gitea.io/gitea 1.20.6 fixed in 1.22.3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-68943 | MEDIUM4.5 | code.gitea.io/gitea 1.20.6 fixed in 1.21.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-68944 | MEDIUM4.5 | code.gitea.io/gitea 1.20.6 fixed in 1.22.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-68945 | MEDIUM4.5 | code.gitea.io/gitea 1.20.6 fixed in 1.21.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-69413 | MEDIUM4.5 | code.gitea.io/gitea 1.20.6 fixed in 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-68940 | MEDIUM4.5 | code.gitea.io/gitea 1.20.6 fixed in 1.22.5 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-58058 | MEDIUM4.5 | github.com/ulikunitz/xz v0.5.11 fixed in 0.5.15 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-47914 | MEDIUM4.5 | golang.org/x/crypto v0.11.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-58181 | MEDIUM4.5 | golang.org/x/crypto v0.11.0 fixed in 0.45.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-46598 | MEDIUM4.5 | golang.org/x/crypto v0.11.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-47911 | MEDIUM4.5 | golang.org/x/net v0.13.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-58190 | MEDIUM4.5 | golang.org/x/net v0.13.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-22866 | MEDIUM4.5 | stdlib v1.20.11 fixed in 1.22.12, 1.23.6, 1.24.0-rc.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-22873 | MEDIUM4.5 | stdlib v1.20.11 fixed in 1.23.9, 1.24.3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-47912 | MEDIUM4.5 | stdlib v1.20.11 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-58185 | MEDIUM4.5 | stdlib v1.20.11 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-58187 | MEDIUM4.5 | stdlib v1.20.11 fixed in 1.24.9, 1.25.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-58188 | MEDIUM4.5 | stdlib v1.20.11 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-58189 | MEDIUM4.5 | stdlib v1.20.11 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-61723 | MEDIUM4.5 | stdlib v1.20.11 fixed in 1.24.8, 1.25.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-61724 | MEDIUM4.5 | stdlib v1.20.11 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-61725 | MEDIUM4.5 | stdlib v1.20.11 fixed in 1.24.8, 1.25.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-61730 | MEDIUM4.5 | stdlib v1.20.11 fixed in 1.24.12, 1.25.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42505 | MEDIUM4.5 | stdlib v1.20.11 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42507 | MEDIUM4.5 | stdlib v1.20.11 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-58186 | MEDIUM4.5 | stdlib v1.20.11 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-28835 | MEDIUM4.25 | gnutls 3.8.0-r2 fixed in 3.8.4-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34165 | MEDIUM4.25 | github.com/go-git/go-git/v5 v5.6.1 fixed in 5.17.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-1386 | MEDIUM4.17 | github.com/ClickHouse/ch-go v0.55.0 fixed in 0.65.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-13176 | MEDIUM4 | libcrypto3 3.1.3-r0 fixed in 3.1.8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-13176 | MEDIUM4 | libssl3 3.1.3-r0 fixed in 3.1.8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-32465 | LOW3.98 | git 2.40.1-r0 fixed in 2.40.3-r0 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2024-9681 | LOW3.9 | curl 8.4.0-r0 fixed in 8.11.0-r0 | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2023-46218 | LOW3.9 | libcurl 8.4.0-r0 fixed in 8.5.0-r0 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-9681 | LOW3.9 | libcurl 8.4.0-r0 fixed in 8.11.0-r0 | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2025-22870 | LOW3.74 | golang.org/x/net v0.13.0 fixed in 0.36.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-22870 | LOW3.74 | stdlib v1.20.11 fixed in 1.23.7, 1.24.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-9143 | LOW3.7 | libcrypto3 3.1.3-r0 fixed in 3.1.7-r1 | 5.8% Low-Moderate Risk | Directly Exposed |
| CVE-2024-9143 | LOW3.7 | libssl3 3.1.3-r0 fixed in 3.1.7-r1 | 5.8% Low-Moderate Risk | Directly Exposed |
| CVE-2026-25934 | LOW3.65 | github.com/go-git/go-git/v5 v5.6.1 fixed in 5.16.5 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2024-32021 | LOW3.62 | git 2.40.1-r0 fixed in 2.40.3-r0 | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2025-6965 | LOW3.61 | sqlite-libs 3.41.2-r2 fixed in 3.41.2-r4 | 74.4% Actively Exploited | Post-Exploit |
| CVE-2024-45341 | LOW3.57 | stdlib v1.20.11 fixed in 1.22.11, 1.23.5, 1.24.0-rc.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-11053 | LOW3.54 | curl 8.4.0-r0 fixed in 8.11.1-r0 | 1.4% Low-Moderate Risk | Post-Exploit |
| CVE-2024-11053 | LOW3.54 | libcurl 8.4.0-r0 fixed in 8.11.1-r0 | 1.4% Low-Moderate Risk | Post-Exploit |
| CVE-2024-45491 | LOW3.53 | libexpat 2.5.0-r1 fixed in 2.6.3-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2024-45492 | LOW3.53 | libexpat 2.5.0-r1 fixed in 2.6.3-r0 | 1.4% Low-Moderate Risk | Post-Exploit |
| CVE-2024-56171 | LOW3.53 | libxml2 2.11.6-r0 fixed in 2.11.8-r1 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2024-6119 | LOW3.51 | libcrypto3 3.1.3-r0 fixed in 3.1.7-r0 | 66.6% Actively Exploited | Post-Exploit |
| CVE-2024-6119 | LOW3.51 | libssl3 3.1.3-r0 fixed in 3.1.7-r0 | 66.6% Actively Exploited | Post-Exploit |
| CVE-2024-8096 | LOW3.31 | curl 8.4.0-r0 fixed in 8.10.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2024-8096 | LOW3.31 | libcurl 8.4.0-r0 fixed in 8.10.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-33186 | LOW3.28 | google.golang.org/grpc v1.53.0 fixed in 1.79.3 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2379 | LOW3.24 | curl 8.4.0-r0 fixed in 8.7.1-r0 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2379 | LOW3.24 | libcurl 8.4.0-r0 fixed in 8.7.1-r0 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2023-46219 | LOW3.18 | curl 8.4.0-r0 fixed in 8.5.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2024-0853 | LOW3.18 | curl 8.4.0-r0 fixed in 8.6.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2466 | LOW3.18 | curl 8.4.0-r0 fixed in 8.7.1-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2004 | LOW3.18 | curl 8.4.0-r0 fixed in 8.7.1-r0 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2023-46219 | LOW3.18 | libcurl 8.4.0-r0 fixed in 8.5.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2024-0853 | LOW3.18 | libcurl 8.4.0-r0 fixed in 8.6.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2466 | LOW3.18 | libcurl 8.4.0-r0 fixed in 8.7.1-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2004 | LOW3.18 | libcurl 8.4.0-r0 fixed in 8.7.1-r0 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2025-8556 | LOW3.15 | github.com/cloudflare/circl v1.3.3 fixed in 1.6.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-2398 | LOW3.1 | curl 8.4.0-r0 fixed in 8.7.1-r0 | 36.1% High Exploitation Risk | Post-Exploit |
| CVE-2024-2398 | LOW3.1 | libcurl 8.4.0-r0 fixed in 8.7.1-r0 | 36.1% High Exploitation Risk | Post-Exploit |
| CVE-2026-1229 | LOW3 | github.com/cloudflare/circl v1.3.3 fixed in 1.6.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-0798 | LOW2.98 | code.gitea.io/gitea 1.20.6 fixed in 1.25.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-45570 | LOW2.94 | github.com/go-git/go-git/v5 v5.6.1 fixed in 5.19.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-21613 | LOW2.92 | github.com/go-git/go-git/v5 v5.6.1 fixed in 5.13.0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2024-32004 | LOW2.81 | git 2.40.1-r0 fixed in 2.40.3-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2023-42363 | LOW2.8 | busybox 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42364 | LOW2.8 | busybox 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42365 | LOW2.8 | busybox 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42366 | LOW2.8 | busybox 1.36.1-r2 fixed in 1.36.1-r6 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42363 | LOW2.8 | busybox-binsh 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42364 | LOW2.8 | busybox-binsh 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42365 | LOW2.8 | busybox-binsh 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42366 | LOW2.8 | busybox-binsh 1.36.1-r2 fixed in 1.36.1-r6 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42363 | LOW2.8 | ssl_client 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42364 | LOW2.8 | ssl_client 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42365 | LOW2.8 | ssl_client 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42366 | LOW2.8 | ssl_client 1.36.1-r2 fixed in 1.36.1-r6 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-6197 | LOW2.7 | curl 8.4.0-r0 fixed in 8.9.0-r0 | 4.3% Low-Moderate Risk | Post-Exploit |
| CVE-2024-52006 | LOW2.7 | git 2.40.1-r0 fixed in 2.40.4-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2024-6197 | LOW2.7 | libcurl 8.4.0-r0 fixed in 8.9.0-r0 | 4.3% Low-Moderate Risk | Post-Exploit |
| CVE-2023-52425 | LOW2.7 | libexpat 2.5.0-r1 fixed in 2.6.0-r0 | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2024-7264 | LOW2.69 | curl 8.4.0-r0 fixed in 8.9.1-r0 | 17.3% High Exploitation Risk | Post-Exploit |
| CVE-2024-7264 | LOW2.69 | libcurl 8.4.0-r0 fixed in 8.9.1-r0 | 17.3% High Exploitation Risk | Post-Exploit |
| CVE-2024-51744 | LOW2.63 | github.com/golang-jwt/jwt/v4 v4.5.0 fixed in 4.5.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-50349 | LOW2.4 | git 2.40.1-r0 fixed in 2.40.4-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-0665 | LOW2.4 | curl 8.4.0-r0 fixed in 8.12.0-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-0725 | LOW2.4 | curl 8.4.0-r0 fixed in 8.12.0-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-0665 | LOW2.4 | libcurl 8.4.0-r0 fixed in 8.12.0-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-0725 | LOW2.4 | libcurl 8.4.0-r0 fixed in 8.12.0-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-33762 | LOW2.38 | github.com/go-git/go-git/v5 v5.6.1 fixed in 5.17.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-46218 | LOW2.34 | curl 8.4.0-r0 fixed in 8.5.0-r0 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-6874 | LOW2.19 | curl 8.4.0-r0 fixed in 8.9.0-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2024-6874 | LOW2.19 | libcurl 8.4.0-r0 fixed in 8.9.0-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-27139 | LOW2.12 | stdlib v1.20.11 fixed in 1.25.8, 1.26.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-32020 | LOW1.68 | git 2.40.1-r0 fixed in 2.40.3-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-26519 | NONE0 | musl-utils 1.2.4-r1 fixed in 1.2.4-r3 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-0167 | NONE0 | curl 8.4.0-r0 fixed in 8.12.0-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2025-0167 | NONE0 | libcurl 8.4.0-r0 fixed in 8.12.0-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-20896 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.3 | 31.8% High Exploitation Risk | Not Applicable |
| CVE-2026-22874 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-56750 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58443 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-20779 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-22555 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-24451 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-25038 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-26231 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-27771 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.2 | 43.1% High Exploitation Risk | Not Applicable |
| CVE-2026-27775 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-28699 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-28744 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54481 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-55987 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-56654 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-56755 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-57894 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58314 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58419 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-58421 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-58422 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-58424 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.3 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-58436 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58437 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-20706 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-25714 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-27761 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-27783 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42931 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-50105 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-55982 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-56443 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-56657 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-57886 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-57897 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58418 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-58425 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58428 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58429 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58432 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58435 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58441 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58442 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58444 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58507 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58510 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-59763 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-59765 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-59766 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| GHSA-3m6q-h5gj-7mrw | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.25.0 | — | Not Applicable |
| GHSA-rjvx-x5h2-6px5 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.26.0 | — | Not Applicable |
| CVE-2026-23603 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-55984 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58434 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58445 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58511 | NONE0 | code.gitea.io/gitea 1.20.6 fixed in 1.27.0 | — | Not Applicable |
| GHSA-9763-4f94-gfch | NONE0 | github.com/cloudflare/circl v1.3.3 fixed in 1.3.7 | — | Not Applicable |
| GHSA-vrw8-fxc6-2r93 | NONE0 | github.com/go-chi/chi/v5 v5.0.8 fixed in 5.2.2 | — | Not Applicable |
| GHSA-w5pp-99ch-qj29 | NONE0 | github.com/go-git/go-git/v5 v5.6.1 fixed in 5.19.1 | — | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.11.0 No fix yet | — | Not Applicable |
| CVE-2026-46602 | NONE0 | golang.org/x/image v0.7.0 fixed in 0.43.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-46604 | NONE0 | golang.org/x/image v0.7.0 fixed in 0.43.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-24792 | NONE0 | golang.org/x/image v0.7.0 fixed in 0.18.0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-42500 | NONE0 | golang.org/x/image v0.7.0 fixed in 0.41.0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-46600 | NONE0 | golang.org/x/net v0.13.0 fixed in 0.56.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39824 | NONE0 | golang.org/x/sys v0.10.0 fixed in 0.44.0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56852 | NONE0 | golang.org/x/text v0.11.0 fixed in 0.39.0 | 0.4% Theoretical Threat | Not Applicable |
| GHSA-hrxh-6v49-42gf | NONE0 | google.golang.org/grpc v1.53.0 fixed in 1.82.1 | — | Not Applicable |
| GHSA-m425-mq94-257g | NONE0 | google.golang.org/grpc v1.53.0 fixed in 1.56.3, 1.57.1, 1.58.3 | — | Not Applicable |
| CVE-2025-0913 | NONE0 | stdlib v1.20.11 fixed in 1.23.10, 1.24.4 | 0.2% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.