Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. The stored XSS (CVE-2024-6886) could allow session hijacking or admin account takeover, while the SSH Terrapin flaw (CVE-2023-48795) could downgrade SSH integrity protections when clients connect through a network attacker. Although 64 post-exploit findings exist, their maximum severity is only 3.98, so the immediate risk is concentrated in the exposed surface. Note that the HTTP/2 DoS only applies when HTTP/2 is exposed; disabling HTTP/2 would fully eliminate that risk.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2024-6886 | CRITICAL10 | code.gitea.io/gitea 1.21.1 fixed in 1.22.1 | 33.0% High Exploitation Risk | Directly ExposedContext importance: HIGH |
| CVE-2024-24790 | HIGH7.84 | stdlib v1.21.4 fixed in 1.21.11, 1.22.4 | 2.0% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2023-45288 | HIGH7.8 | golang.org/x/net v0.17.0 fixed in 0.23.0 | 92.0% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2023-45288 | HIGH7.8 | stdlib v1.21.4 fixed in 1.21.9, 1.22.2 | 92.0% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2023-48795 | HIGH7.67 | golang.org/x/crypto v0.14.0 fixed in 0.17.0 | 93.3% Actively Exploited | Directly ExposedContext importance: HIGH |
| CVE-2024-0553 | HIGH7.5 | gnutls 3.8.0-r2 fixed in 3.8.3-r0 | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2024-0567 | HIGH7.5 | gnutls 3.8.0-r2 fixed in 3.8.3-r0 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2024-28757 | HIGH7.5 | libexpat 2.5.0-r1 fixed in 2.6.2-r0 | 2.0% Low-Moderate Risk | Directly Exposed |
| CVE-2024-45490 | HIGH7.5 | libexpat 2.5.0-r1 fixed in 2.6.3-r0 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2024-8176 | HIGH7.5 | libexpat 2.5.0-r1 fixed in 2.7.0-r0 | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2023-5363 | HIGH7.5 | libssl3 3.1.3-r0 fixed in 3.1.4-r0 | 3.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-25062 | HIGH7.5 | libxml2 2.11.6-r0 fixed in 2.11.7-r0 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2025-27113 | HIGH7.5 | libxml2 2.11.6-r0 fixed in 2.11.8-r2 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-32952 | HIGH7.5 | github.com/Azure/go-ntlmssp v0.0.0-20221128193559-754e69321358 fixed in 0.1.1 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2024-34156 | HIGH7.5 | stdlib v1.21.4 fixed in 1.22.7, 1.23.1 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2025-61726 | HIGH7.5 | stdlib v1.21.4 fixed in 1.24.12, 1.25.6 | 1.9% Low-Moderate Risk | Directly Exposed |
| CVE-2026-39828 | HIGH7.48 | golang.org/x/crypto v0.14.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-39832 | HIGH7.39 | golang.org/x/crypto v0.14.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2023-7104 | HIGH7.3 | sqlite-libs 3.41.2-r2 fixed in 3.41.2-r3 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-39821 | MEDIUM6.97 | golang.org/x/net v0.17.0 fixed in 0.55.0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-44973 | MEDIUM6.88 | github.com/go-git/go-billy/v5 v5.5.0 fixed in 5.9.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-3445 | MEDIUM6.88 | github.com/mholt/archiver/v3 v3.5.1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-39831 | MEDIUM6.88 | golang.org/x/crypto v0.14.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-25681 | MEDIUM6.88 | golang.org/x/net v0.17.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27136 | MEDIUM6.88 | golang.org/x/net v0.17.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-68121 | MEDIUM6.8 | stdlib v1.21.4 fixed in 1.24.13, 1.25.7, 1.26.0-rc.3 | 0.8% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2024-0406 | MEDIUM6.63 | github.com/mholt/archiver/v3 v3.5.1 No fix yet | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-39822 | MEDIUM6.63 | stdlib v1.21.4 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-45337 | MEDIUM6.56 | golang.org/x/crypto v0.14.0 fixed in 0.31.0 | 3.2% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2025-24928 | MEDIUM6.54 | libxml2 2.11.6-r0 fixed in 2.11.8-r1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-6129 | MEDIUM6.5 | libcrypto3 3.1.3-r0 fixed in 3.1.4-r3 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2023-6129 | MEDIUM6.5 | libssl3 3.1.3-r0 fixed in 3.1.4-r3 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-32414 | MEDIUM6.38 | libxml2 2.11.6-r0 fixed in 2.11.8-r3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-32415 | MEDIUM6.38 | libxml2 2.11.6-r0 fixed in 2.11.8-r3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-31115 | MEDIUM6.38 | xz-libs 5.4.3-r0 fixed in 5.4.3-r1 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-20736 | MEDIUM6.38 | code.gitea.io/gitea 1.21.1 fixed in 1.25.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-44740 | MEDIUM6.38 | github.com/go-git/go-billy/v5 v5.5.0 fixed in 5.9.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-49568 | MEDIUM6.38 | github.com/go-git/go-git/v5 v5.9.0 fixed in 5.11.0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-21614 | MEDIUM6.38 | github.com/go-git/go-git/v5 v5.9.0 fixed in 5.13.0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-45022 | MEDIUM6.38 | github.com/go-git/go-git/v5 v5.9.0 fixed in 5.19.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-30204 | MEDIUM6.38 | github.com/golang-jwt/jwt/v4 v4.5.0 fixed in 4.5.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-30204 | MEDIUM6.38 | github.com/golang-jwt/jwt/v5 v5.0.0 fixed in 5.2.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-22869 | MEDIUM6.38 | golang.org/x/crypto v0.14.0 fixed in 0.35.0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-47913 | MEDIUM6.38 | golang.org/x/crypto v0.14.0 fixed in 0.43.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-39829 | MEDIUM6.38 | golang.org/x/crypto v0.14.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-39830 | MEDIUM6.38 | golang.org/x/crypto v0.14.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-39835 | MEDIUM6.38 | golang.org/x/crypto v0.14.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-46597 | MEDIUM6.38 | golang.org/x/crypto v0.14.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-45338 | MEDIUM6.38 | golang.org/x/net v0.17.0 fixed in 0.33.0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-33814 | MEDIUM6.38 | golang.org/x/net v0.17.0 fixed in 0.53.0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-22868 | MEDIUM6.38 | golang.org/x/oauth2 v0.13.0 fixed in 0.27.0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-61729 | MEDIUM6.38 | stdlib v1.21.4 fixed in 1.24.11, 1.25.5 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-25679 | MEDIUM6.38 | stdlib v1.21.4 fixed in 1.25.8, 1.26.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-27145 | MEDIUM6.38 | stdlib v1.21.4 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-32280 | MEDIUM6.38 | stdlib v1.21.4 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-32281 | MEDIUM6.38 | stdlib v1.21.4 fixed in 1.25.9, 1.26.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-32283 | MEDIUM6.38 | stdlib v1.21.4 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-33811 | MEDIUM6.38 | stdlib v1.21.4 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-33814 | MEDIUM6.38 | stdlib v1.21.4 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-39820 | MEDIUM6.38 | stdlib v1.21.4 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-39836 | MEDIUM6.38 | stdlib v1.21.4 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42499 | MEDIUM6.38 | stdlib v1.21.4 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-42504 | MEDIUM6.38 | stdlib v1.21.4 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-58183 | MEDIUM6.38 | stdlib v1.21.4 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-61728 | MEDIUM6.38 | stdlib v1.21.4 fixed in 1.24.12, 1.25.6 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-41506 | MEDIUM6.29 | github.com/go-git/go-git/v5 v5.9.0 fixed in 5.18.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42508 | MEDIUM6.29 | golang.org/x/crypto v0.14.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-46595 | MEDIUM6.03 | golang.org/x/crypto v0.14.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-26519 | MEDIUM5.95 | musl 1.2.4-r1 fixed in 1.2.4-r3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-26519 | MEDIUM5.95 | musl-utils 1.2.4-r1 fixed in 1.2.4-r3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-47907 | MEDIUM5.95 | stdlib v1.21.4 fixed in 1.23.12, 1.24.6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-5981 | MEDIUM5.9 | gnutls 3.8.0-r2 fixed in 3.8.3-r0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2023-6237 | MEDIUM5.9 | libcrypto3 3.1.3-r0 fixed in 3.1.4-r4 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-5535 | MEDIUM5.9 | libcrypto3 3.1.3-r0 fixed in 3.1.6-r0 | 5.6% Low-Moderate Risk | Directly Exposed |
| CVE-2024-50602 | MEDIUM5.9 | libexpat 2.5.0-r1 fixed in 2.6.4-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2023-6237 | MEDIUM5.9 | libssl3 3.1.3-r0 fixed in 3.1.4-r4 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-5535 | MEDIUM5.9 | libssl3 3.1.3-r0 fixed in 3.1.6-r0 | 5.6% Low-Moderate Risk | Directly Exposed |
| CVE-2024-24786 | MEDIUM5.9 | google.golang.org/protobuf v1.31.0 fixed in 1.33.0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-24791 | MEDIUM5.9 | stdlib v1.21.4 fixed in 1.21.12, 1.22.5 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2024-34158 | MEDIUM5.9 | stdlib v1.21.4 fixed in 1.22.7, 1.23.1 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-4673 | MEDIUM5.78 | stdlib v1.21.4 fixed in 1.23.10, 1.24.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-4741 | MEDIUM5.6 | libcrypto3 3.1.3-r0 fixed in 3.1.6-r0 | 2.9% Low-Moderate Risk | Directly Exposed |
| CVE-2024-4741 | MEDIUM5.6 | libssl3 3.1.3-r0 fixed in 3.1.6-r0 | 2.9% Low-Moderate Risk | Directly Exposed |
| CVE-2025-11579 | MEDIUM5.52 | github.com/nwaples/rardecode v1.1.3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39827 | MEDIUM5.52 | golang.org/x/crypto v0.14.0 fixed in 0.52.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39834 | MEDIUM5.52 | golang.org/x/crypto v0.14.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-33809 | MEDIUM5.52 | golang.org/x/image v0.13.0 fixed in 0.38.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-33813 | MEDIUM5.52 | golang.org/x/image v0.13.0 fixed in 0.42.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-46599 | MEDIUM5.52 | golang.org/x/image v0.13.0 fixed in 0.41.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-46601 | MEDIUM5.52 | golang.org/x/image v0.13.0 fixed in 0.43.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-22872 | MEDIUM5.52 | golang.org/x/net v0.17.0 fixed in 0.38.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-25680 | MEDIUM5.52 | golang.org/x/net v0.17.0 fixed in 0.55.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-24785 | MEDIUM5.52 | stdlib v1.21.4 fixed in 1.21.8, 1.22.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-47906 | MEDIUM5.52 | stdlib v1.21.4 fixed in 1.23.12, 1.24.6 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-61727 | MEDIUM5.52 | stdlib v1.21.4 fixed in 1.24.11, 1.25.5 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39825 | MEDIUM5.52 | stdlib v1.21.4 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-0727 | MEDIUM5.5 | libcrypto3 3.1.3-r0 fixed in 3.1.4-r5 | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-0727 | MEDIUM5.5 | libssl3 3.1.3-r0 fixed in 3.1.4-r5 | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-34459 | MEDIUM5.5 | libxml2 2.11.6-r0 fixed in 2.11.8-r0 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-32282 | MEDIUM5.44 | stdlib v1.21.4 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-24784 | MEDIUM5.4 | stdlib v1.21.4 fixed in 1.21.8, 1.22.1 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2023-5678 | MEDIUM5.3 | libcrypto3 3.1.3-r0 fixed in 3.1.4-r1 | 4.5% Low-Moderate Risk | Directly Exposed |
| CVE-2024-4603 | MEDIUM5.3 | libcrypto3 3.1.3-r0 fixed in 3.1.5-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-5678 | MEDIUM5.3 | libssl3 3.1.3-r0 fixed in 3.1.4-r1 | 4.5% Low-Moderate Risk | Directly Exposed |
| CVE-2024-4603 | MEDIUM5.3 | libssl3 3.1.3-r0 fixed in 3.1.5-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-12133 | MEDIUM5.3 | libtasn1 4.19.0-r1 fixed in 4.20.0-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-39326 | MEDIUM5.3 | stdlib v1.21.4 fixed in 1.20.12, 1.21.5 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2023-45289 | MEDIUM5.3 | stdlib v1.21.4 fixed in 1.21.8, 1.22.1 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-45290 | MEDIUM5.3 | stdlib v1.21.4 fixed in 1.21.8, 1.22.1 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33812 | MEDIUM5.18 | golang.org/x/image v0.13.0 fixed in 0.39.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-42502 | MEDIUM5.18 | golang.org/x/net v0.17.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32289 | MEDIUM5.18 | stdlib v1.21.4 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-24783 | MEDIUM5.02 | stdlib v1.21.4 fixed in 1.21.8, 1.22.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2024-34155 | MEDIUM5.02 | stdlib v1.21.4 fixed in 1.22.7, 1.23.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-45336 | MEDIUM5.02 | stdlib v1.21.4 fixed in 1.22.11, 1.23.5, 1.24.0-rc.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2024-2511 | MEDIUM4.81 | libcrypto3 3.1.3-r0 fixed in 3.1.4-r6 | 54.0% Actively Exploited | Directly Exposed |
| CVE-2024-2511 | MEDIUM4.81 | libssl3 3.1.3-r0 fixed in 3.1.4-r6 | 54.0% Actively Exploited | Directly Exposed |
| CVE-2023-52426 | MEDIUM4.67 | libexpat 2.5.0-r1 fixed in 2.6.0-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2022-31022 | MEDIUM4.67 | github.com/blevesearch/bleve/v2 v2.3.10 fixed in 2.5.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-6104 | MEDIUM4.67 | github.com/hashicorp/go-retryablehttp v0.7.4 fixed in 0.7.7 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-39833 | MEDIUM4.67 | golang.org/x/crypto v0.14.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-24789 | MEDIUM4.67 | stdlib v1.21.4 fixed in 1.21.11, 1.22.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-32288 | MEDIUM4.67 | stdlib v1.21.4 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-68942 | MEDIUM4.59 | code.gitea.io/gitea 1.21.1 fixed in 1.22.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-45571 | MEDIUM4.59 | github.com/go-git/go-git/v5 v5.9.0 fixed in 5.19.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42506 | MEDIUM4.59 | golang.org/x/net v0.17.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-22871 | MEDIUM4.59 | stdlib v1.21.4 fixed in 1.23.8, 1.24.2 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-27142 | MEDIUM4.59 | stdlib v1.21.4 fixed in 1.25.8, 1.26.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39823 | MEDIUM4.59 | stdlib v1.21.4 fixed in 1.25.10, 1.26.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39826 | MEDIUM4.59 | stdlib v1.21.4 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-28834 | MEDIUM4.5 | gnutls 3.8.0-r2 fixed in 3.8.4-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-68939 | MEDIUM4.5 | code.gitea.io/gitea 1.21.1 fixed in 1.23.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-68938 | MEDIUM4.5 | code.gitea.io/gitea 1.21.1 fixed in 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-68941 | MEDIUM4.5 | code.gitea.io/gitea 1.21.1 fixed in 1.22.3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-68943 | MEDIUM4.5 | code.gitea.io/gitea 1.21.1 fixed in 1.21.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-68944 | MEDIUM4.5 | code.gitea.io/gitea 1.21.1 fixed in 1.22.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-68945 | MEDIUM4.5 | code.gitea.io/gitea 1.21.1 fixed in 1.21.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-69413 | MEDIUM4.5 | code.gitea.io/gitea 1.21.1 fixed in 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-68940 | MEDIUM4.5 | code.gitea.io/gitea 1.21.1 fixed in 1.22.5 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-58058 | MEDIUM4.5 | github.com/ulikunitz/xz v0.5.11 fixed in 0.5.15 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-47914 | MEDIUM4.5 | golang.org/x/crypto v0.14.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-58181 | MEDIUM4.5 | golang.org/x/crypto v0.14.0 fixed in 0.45.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-46598 | MEDIUM4.5 | golang.org/x/crypto v0.14.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-47911 | MEDIUM4.5 | golang.org/x/net v0.17.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-58190 | MEDIUM4.5 | golang.org/x/net v0.17.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-22866 | MEDIUM4.5 | stdlib v1.21.4 fixed in 1.22.12, 1.23.6, 1.24.0-rc.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-22873 | MEDIUM4.5 | stdlib v1.21.4 fixed in 1.23.9, 1.24.3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-47912 | MEDIUM4.5 | stdlib v1.21.4 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-58185 | MEDIUM4.5 | stdlib v1.21.4 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-58187 | MEDIUM4.5 | stdlib v1.21.4 fixed in 1.24.9, 1.25.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-58188 | MEDIUM4.5 | stdlib v1.21.4 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-58189 | MEDIUM4.5 | stdlib v1.21.4 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-61723 | MEDIUM4.5 | stdlib v1.21.4 fixed in 1.24.8, 1.25.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-61724 | MEDIUM4.5 | stdlib v1.21.4 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-61725 | MEDIUM4.5 | stdlib v1.21.4 fixed in 1.24.8, 1.25.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-61730 | MEDIUM4.5 | stdlib v1.21.4 fixed in 1.24.12, 1.25.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42505 | MEDIUM4.5 | stdlib v1.21.4 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42507 | MEDIUM4.5 | stdlib v1.21.4 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-58186 | MEDIUM4.5 | stdlib v1.21.4 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-28835 | MEDIUM4.25 | gnutls 3.8.0-r2 fixed in 3.8.4-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34165 | MEDIUM4.25 | github.com/go-git/go-git/v5 v5.9.0 fixed in 5.17.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-1386 | MEDIUM4.17 | github.com/ClickHouse/ch-go v0.58.2 fixed in 0.65.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-13176 | MEDIUM4 | libcrypto3 3.1.3-r0 fixed in 3.1.8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-13176 | MEDIUM4 | libssl3 3.1.3-r0 fixed in 3.1.8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-32465 | LOW3.98 | git 2.40.1-r0 fixed in 2.40.3-r0 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2024-9681 | LOW3.9 | curl 8.4.0-r0 fixed in 8.11.0-r0 | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2023-46218 | LOW3.9 | libcurl 8.4.0-r0 fixed in 8.5.0-r0 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-9681 | LOW3.9 | libcurl 8.4.0-r0 fixed in 8.11.0-r0 | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2025-22870 | LOW3.74 | golang.org/x/net v0.17.0 fixed in 0.36.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-22870 | LOW3.74 | stdlib v1.21.4 fixed in 1.23.7, 1.24.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-32002 | LOW3.73 | git 2.40.1-r0 fixed in 2.40.3-r0 | 25.3% High Exploitation Risk | Post-Exploit |
| CVE-2024-9143 | LOW3.7 | libcrypto3 3.1.3-r0 fixed in 3.1.7-r1 | 5.8% Low-Moderate Risk | Directly Exposed |
| CVE-2024-9143 | LOW3.7 | libssl3 3.1.3-r0 fixed in 3.1.7-r1 | 5.8% Low-Moderate Risk | Directly Exposed |
| CVE-2026-25934 | LOW3.65 | github.com/go-git/go-git/v5 v5.9.0 fixed in 5.16.5 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2024-32021 | LOW3.62 | git 2.40.1-r0 fixed in 2.40.3-r0 | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2025-6965 | LOW3.61 | sqlite-libs 3.41.2-r2 fixed in 3.41.2-r4 | 74.4% Actively Exploited | Post-Exploit |
| CVE-2024-45341 | LOW3.57 | stdlib v1.21.4 fixed in 1.22.11, 1.23.5, 1.24.0-rc.2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-11053 | LOW3.54 | curl 8.4.0-r0 fixed in 8.11.1-r0 | 1.4% Low-Moderate Risk | Post-Exploit |
| CVE-2024-11053 | LOW3.54 | libcurl 8.4.0-r0 fixed in 8.11.1-r0 | 1.4% Low-Moderate Risk | Post-Exploit |
| CVE-2024-45491 | LOW3.53 | libexpat 2.5.0-r1 fixed in 2.6.3-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2024-45492 | LOW3.53 | libexpat 2.5.0-r1 fixed in 2.6.3-r0 | 1.4% Low-Moderate Risk | Post-Exploit |
| CVE-2024-56171 | LOW3.53 | libxml2 2.11.6-r0 fixed in 2.11.8-r1 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2023-49569 | LOW3.53 | github.com/go-git/go-git/v5 v5.9.0 fixed in 5.11.0 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2024-6119 | LOW3.51 | libcrypto3 3.1.3-r0 fixed in 3.1.7-r0 | 66.6% Actively Exploited | Post-Exploit |
| CVE-2024-6119 | LOW3.51 | libssl3 3.1.3-r0 fixed in 3.1.7-r0 | 66.6% Actively Exploited | Post-Exploit |
| CVE-2024-8096 | LOW3.31 | curl 8.4.0-r0 fixed in 8.10.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2024-8096 | LOW3.31 | libcurl 8.4.0-r0 fixed in 8.10.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-33186 | LOW3.28 | google.golang.org/grpc v1.58.3 fixed in 1.79.3 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2379 | LOW3.24 | curl 8.4.0-r0 fixed in 8.7.1-r0 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2379 | LOW3.24 | libcurl 8.4.0-r0 fixed in 8.7.1-r0 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2023-46219 | LOW3.18 | curl 8.4.0-r0 fixed in 8.5.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2024-0853 | LOW3.18 | curl 8.4.0-r0 fixed in 8.6.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2466 | LOW3.18 | curl 8.4.0-r0 fixed in 8.7.1-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2004 | LOW3.18 | curl 8.4.0-r0 fixed in 8.7.1-r0 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2023-46219 | LOW3.18 | libcurl 8.4.0-r0 fixed in 8.5.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2024-0853 | LOW3.18 | libcurl 8.4.0-r0 fixed in 8.6.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2466 | LOW3.18 | libcurl 8.4.0-r0 fixed in 8.7.1-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2004 | LOW3.18 | libcurl 8.4.0-r0 fixed in 8.7.1-r0 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2025-8556 | LOW3.15 | github.com/cloudflare/circl v1.3.3 fixed in 1.6.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-2398 | LOW3.1 | curl 8.4.0-r0 fixed in 8.7.1-r0 | 36.1% High Exploitation Risk | Post-Exploit |
| CVE-2024-2398 | LOW3.1 | libcurl 8.4.0-r0 fixed in 8.7.1-r0 | 36.1% High Exploitation Risk | Post-Exploit |
| CVE-2026-1229 | LOW3 | github.com/cloudflare/circl v1.3.3 fixed in 1.6.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-0798 | LOW2.98 | code.gitea.io/gitea 1.21.1 fixed in 1.25.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-45570 | LOW2.94 | github.com/go-git/go-git/v5 v5.9.0 fixed in 5.19.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-21613 | LOW2.92 | github.com/go-git/go-git/v5 v5.9.0 fixed in 5.13.0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2024-32004 | LOW2.81 | git 2.40.1-r0 fixed in 2.40.3-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2023-42363 | LOW2.8 | busybox 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42364 | LOW2.8 | busybox 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42365 | LOW2.8 | busybox 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42366 | LOW2.8 | busybox 1.36.1-r2 fixed in 1.36.1-r6 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42363 | LOW2.8 | busybox-binsh 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42364 | LOW2.8 | busybox-binsh 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42365 | LOW2.8 | busybox-binsh 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42366 | LOW2.8 | busybox-binsh 1.36.1-r2 fixed in 1.36.1-r6 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42363 | LOW2.8 | ssl_client 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42364 | LOW2.8 | ssl_client 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42365 | LOW2.8 | ssl_client 1.36.1-r2 fixed in 1.36.1-r7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-42366 | LOW2.8 | ssl_client 1.36.1-r2 fixed in 1.36.1-r6 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-6197 | LOW2.7 | curl 8.4.0-r0 fixed in 8.9.0-r0 | 4.3% Low-Moderate Risk | Post-Exploit |
| CVE-2024-52006 | LOW2.7 | git 2.40.1-r0 fixed in 2.40.4-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2023-5363 | LOW2.7 | libcrypto3 3.1.3-r0 fixed in 3.1.4-r0 | 3.3% Low-Moderate Risk | Post-Exploit |
| CVE-2024-6197 | LOW2.7 | libcurl 8.4.0-r0 fixed in 8.9.0-r0 | 4.3% Low-Moderate Risk | Post-Exploit |
| CVE-2023-52425 | LOW2.7 | libexpat 2.5.0-r1 fixed in 2.6.0-r0 | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2024-7264 | LOW2.69 | curl 8.4.0-r0 fixed in 8.9.1-r0 | 17.3% High Exploitation Risk | Post-Exploit |
| CVE-2024-7264 | LOW2.69 | libcurl 8.4.0-r0 fixed in 8.9.1-r0 | 17.3% High Exploitation Risk | Post-Exploit |
| CVE-2024-51744 | LOW2.63 | github.com/golang-jwt/jwt/v4 v4.5.0 fixed in 4.5.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-50349 | LOW2.4 | git 2.40.1-r0 fixed in 2.40.4-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-0665 | LOW2.4 | curl 8.4.0-r0 fixed in 8.12.0-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-0725 | LOW2.4 | curl 8.4.0-r0 fixed in 8.12.0-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-0665 | LOW2.4 | libcurl 8.4.0-r0 fixed in 8.12.0-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-0725 | LOW2.4 | libcurl 8.4.0-r0 fixed in 8.12.0-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-33762 | LOW2.38 | github.com/go-git/go-git/v5 v5.9.0 fixed in 5.17.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-46218 | LOW2.34 | curl 8.4.0-r0 fixed in 8.5.0-r0 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-6874 | LOW2.19 | curl 8.4.0-r0 fixed in 8.9.0-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2024-6874 | LOW2.19 | libcurl 8.4.0-r0 fixed in 8.9.0-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-27139 | LOW2.12 | stdlib v1.21.4 fixed in 1.25.8, 1.26.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-32020 | LOW1.68 | git 2.40.1-r0 fixed in 2.40.3-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-0167 | NONE0 | curl 8.4.0-r0 fixed in 8.12.0-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2025-0167 | NONE0 | libcurl 8.4.0-r0 fixed in 8.12.0-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-20896 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.3 | 31.8% High Exploitation Risk | Not Applicable |
| CVE-2026-22874 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-56750 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58443 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-20779 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-22555 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-24451 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-25038 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-26231 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-27771 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.2 | 43.1% High Exploitation Risk | Not Applicable |
| CVE-2026-27775 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-28699 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-28744 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54481 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-55987 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-56654 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-56755 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-57894 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58314 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58419 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-58421 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-58422 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-58424 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.3 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-58436 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58437 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-20706 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-25714 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-27761 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-27783 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42931 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-50105 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-55982 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-56443 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-56657 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-57886 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-57897 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58418 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-58425 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58428 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58429 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58432 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58435 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58441 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58442 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58444 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58507 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58510 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-59763 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-59765 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-59766 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| GHSA-3m6q-h5gj-7mrw | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.25.0 | — | Not Applicable |
| GHSA-rjvx-x5h2-6px5 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.26.0 | — | Not Applicable |
| CVE-2026-23603 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-55984 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58434 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58445 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58511 | NONE0 | code.gitea.io/gitea 1.21.1 fixed in 1.27.0 | — | Not Applicable |
| GHSA-9763-4f94-gfch | NONE0 | github.com/cloudflare/circl v1.3.3 fixed in 1.3.7 | — | Not Applicable |
| GHSA-vrw8-fxc6-2r93 | NONE0 | github.com/go-chi/chi/v5 v5.0.10 fixed in 5.2.2 | — | Not Applicable |
| GHSA-w5pp-99ch-qj29 | NONE0 | github.com/go-git/go-git/v5 v5.9.0 fixed in 5.19.1 | — | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.14.0 No fix yet | — | Not Applicable |
| CVE-2026-46602 | NONE0 | golang.org/x/image v0.13.0 fixed in 0.43.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-46604 | NONE0 | golang.org/x/image v0.13.0 fixed in 0.43.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-24792 | NONE0 | golang.org/x/image v0.13.0 fixed in 0.18.0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-42500 | NONE0 | golang.org/x/image v0.13.0 fixed in 0.41.0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-46600 | NONE0 | golang.org/x/net v0.17.0 fixed in 0.56.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39824 | NONE0 | golang.org/x/sys v0.13.0 fixed in 0.44.0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56852 | NONE0 | golang.org/x/text v0.13.0 fixed in 0.39.0 | 0.4% Theoretical Threat | Not Applicable |
| GHSA-hrxh-6v49-42gf | NONE0 | google.golang.org/grpc v1.58.3 fixed in 1.82.1 | — | Not Applicable |
| CVE-2025-0913 | NONE0 | stdlib v1.21.4 fixed in 1.23.10, 1.24.4 | 0.2% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.