Vulnerability Reportgitea/gitea:1.23.0-rootless

gitea/gitea:1.23.0-rootless
digestsha256:e168e42a596a02f74423fc637f1a6eb4ce89dd861df5e533e14c653b737464d9

Executive Summary

Last scanned:

Threat Score
74/100CAUTION
Reputation
RELIABLE

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could remotely crash the service via crafted DNS responses (CVE-2026-33630), malicious DTLS handshakes (CVE-2026-33846), or malformed CRLs (CVE-2026-28388), all without authentication. While the top findings are denial-of-service only—no remote code execution or data exposure was listed—the 17 high-severity exposed vulnerabilities present a real availability risk for any internet-facing Gitea server. Patching these libraries is strongly recommended, and network-layer filtering (e.g., restricting DNS/TLS/DTLS inputs to trusted peers) can reduce the attack surface. Note that the image is pinned by digest and from a trusted community publisher, but that does not mitigate these library flaws.

Vulnerabilities

Vulnerability Log

356 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-33630HIGH7.5
c-ares
1.34.3-r0
fixed in 1.34.8-r0
Directly Exposed
CVE-2026-1584HIGH7.5
gnutls
3.8.8-r0
fixed in 3.8.12-r0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-33846HIGH7.5
gnutls
3.8.8-r0
fixed in 3.8.13-r0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-42009HIGH7.5
gnutls
3.8.8-r0
fixed in 3.8.13-r0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-28388HIGH7.5
libcrypto3
3.3.2-r4
fixed in 3.3.7-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-28389HIGH7.5
libcrypto3
3.3.2-r4
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-28390HIGH7.5
libcrypto3
3.3.2-r4
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-28388HIGH7.5
libssl3
3.3.2-r4
fixed in 3.3.7-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-28389HIGH7.5
libssl3
3.3.2-r4
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-28390HIGH7.5
libssl3
3.3.2-r4
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-2100HIGH7.5
p11-kit
0.25.5-r2
fixed in 0.26.2-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-32952HIGH7.5
github.com/Azure/go-ntlmssp
v0.0.0-20221128193559-754e69321358
fixed in 0.1.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-61726HIGH7.5
stdlib
v1.23.4
fixed in 1.24.12, 1.25.6
1.9%
Low-Moderate Risk
Directly Exposed
CVE-2026-39828HIGH7.48
golang.org/x/crypto
v0.32.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-12797HIGH7.4
libcrypto3
3.3.2-r4
fixed in 3.3.3-r0
2.4%
Low-Moderate Risk
Directly Exposed
CVE-2024-12797HIGH7.4
libssl3
3.3.2-r4
fixed in 3.3.3-r0
2.4%
Low-Moderate Risk
Directly Exposed
CVE-2026-39832HIGH7.39
golang.org/x/crypto
v0.32.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-32990MEDIUM6.97
gnutls
3.8.8-r0
fixed in 3.8.12-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42013MEDIUM6.97
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5260MEDIUM6.97
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-39821MEDIUM6.97
golang.org/x/net
v0.34.0
fixed in 0.55.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM6.88
libcrypto3
3.3.2-r4
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM6.88
libssl3
3.3.2-r4
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-44973MEDIUM6.88
github.com/go-git/go-billy/v5
v5.6.1
fixed in 5.9.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39831MEDIUM6.88
golang.org/x/crypto
v0.32.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-25681MEDIUM6.88
golang.org/x/net
v0.34.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27136MEDIUM6.88
golang.org/x/net
v0.34.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-25210MEDIUM6.63
libexpat
2.6.4-r0
fixed in 2.7.4-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40200MEDIUM6.63
musl
1.2.5-r8
fixed in 1.2.5-r11
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22184MEDIUM6.63
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39822MEDIUM6.63
stdlib
v1.23.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-24928MEDIUM6.54
libxml2
2.13.4-r3
fixed in 2.13.4-r4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45570MEDIUM6.53
github.com/go-git/go-git/v5
v5.13.1
fixed in 5.19.1
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-69421MEDIUM6.38
libcrypto3
3.3.2-r4
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-45186MEDIUM6.38
libexpat
2.6.4-r0
fixed in 2.8.1-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69421MEDIUM6.38
libssl3
3.3.2-r4
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-32414MEDIUM6.38
libxml2
2.13.4-r3
fixed in 2.13.4-r6
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-32415MEDIUM6.38
libxml2
2.13.4-r3
fixed in 2.13.4-r6
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-49795MEDIUM6.38
libxml2
2.13.4-r3
fixed in 2.13.9-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-6732MEDIUM6.38
libxml2
2.13.4-r3
fixed in 2.13.9-r1
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-27135MEDIUM6.38
nghttp2-libs
1.64.0-r0
fixed in 1.68.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-29087MEDIUM6.38
sqlite-libs
3.47.1-r0
fixed in 3.48.0-r1
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-31115MEDIUM6.38
xz-libs
5.6.3-r0
fixed in 5.6.3-r1
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-20736MEDIUM6.38
code.gitea.io/gitea
1.23.0
fixed in 1.25.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-44740MEDIUM6.38
github.com/go-git/go-billy/v5
v5.6.1
fixed in 5.9.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45022MEDIUM6.38
github.com/go-git/go-git/v5
v5.13.1
fixed in 5.19.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-30204MEDIUM6.38
github.com/golang-jwt/jwt/v4
v4.5.1
fixed in 4.5.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-30204MEDIUM6.38
github.com/golang-jwt/jwt/v5
v5.2.1
fixed in 5.2.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-22869MEDIUM6.38
golang.org/x/crypto
v0.32.0
fixed in 0.35.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2025-47913MEDIUM6.38
golang.org/x/crypto
v0.32.0
fixed in 0.43.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39829MEDIUM6.38
golang.org/x/crypto
v0.32.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-39830MEDIUM6.38
golang.org/x/crypto
v0.32.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39835MEDIUM6.38
golang.org/x/crypto
v0.32.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-46597MEDIUM6.38
golang.org/x/crypto
v0.32.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
golang.org/x/net
v0.34.0
fixed in 0.53.0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-22868MEDIUM6.38
golang.org/x/oauth2
v0.23.0
fixed in 0.27.0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-61729MEDIUM6.38
stdlib
v1.23.4
fixed in 1.24.11, 1.25.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-25679MEDIUM6.38
stdlib
v1.23.4
fixed in 1.25.8, 1.26.1
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-27145MEDIUM6.38
stdlib
v1.23.4
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-32280MEDIUM6.38
stdlib
v1.23.4
fixed in 1.25.9, 1.26.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-32281MEDIUM6.38
stdlib
v1.23.4
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32283MEDIUM6.38
stdlib
v1.23.4
fixed in 1.25.9, 1.26.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33811MEDIUM6.38
stdlib
v1.23.4
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
stdlib
v1.23.4
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-39820MEDIUM6.38
stdlib
v1.23.4
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-39836MEDIUM6.38
stdlib
v1.23.4
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42499MEDIUM6.38
stdlib
v1.23.4
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-42504MEDIUM6.38
stdlib
v1.23.4
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-58183MEDIUM6.38
stdlib
v1.23.4
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61728MEDIUM6.38
stdlib
v1.23.4
fixed in 1.24.12, 1.25.6
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-3833MEDIUM6.29
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42011MEDIUM6.29
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-69419MEDIUM6.29
libcrypto3
3.3.2-r4
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69419MEDIUM6.29
libssl3
3.3.2-r4
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41506MEDIUM6.29
github.com/go-git/go-git/v5
v5.13.1
fixed in 5.18.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42508MEDIUM6.29
golang.org/x/crypto
v0.32.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-59937MEDIUM6.18
github.com/wneessen/go-mail
v0.5.2
fixed in 0.7.1
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42012MEDIUM6.03
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-46595MEDIUM6.03
golang.org/x/crypto
v0.32.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-31498MEDIUM5.95
c-ares
1.34.3-r0
fixed in 1.34.5-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-26519MEDIUM5.95
musl
1.2.5-r8
fixed in 1.2.5-r9
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-47907MEDIUM5.95
stdlib
v1.23.4
fixed in 1.23.12, 1.24.6
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-9231MEDIUM5.9
libcrypto3
3.3.2-r4
fixed in 3.3.5-r0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-31790MEDIUM5.9
libcrypto3
3.3.2-r4
fixed in 3.3.7-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-9231MEDIUM5.9
libssl3
3.3.2-r4
fixed in 3.3.5-r0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-31790MEDIUM5.9
libssl3
3.3.2-r4
fixed in 3.3.7-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-13151MEDIUM5.9
libtasn1
4.19.0-r2
fixed in 4.21.0-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-56132MEDIUM5.87
libexpat
2.6.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56403MEDIUM5.87
libexpat
2.6.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56404MEDIUM5.87
libexpat
2.6.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56405MEDIUM5.87
libexpat
2.6.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56406MEDIUM5.87
libexpat
2.6.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56407MEDIUM5.87
libexpat
2.6.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56410MEDIUM5.87
libexpat
2.6.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56411MEDIUM5.87
libexpat
2.6.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-4673MEDIUM5.78
stdlib
v1.23.4
fixed in 1.23.10, 1.24.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42014MEDIUM5.61
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-9230MEDIUM5.6
libcrypto3
3.3.2-r4
fixed in 3.3.5-r0
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2025-9230MEDIUM5.6
libssl3
3.3.2-r4
fixed in 3.3.5-r0
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2025-6395MEDIUM5.52
gnutls
3.8.8-r0
fixed in 3.8.12-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-11579MEDIUM5.52
github.com/nwaples/rardecode
v1.1.3
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39827MEDIUM5.52
golang.org/x/crypto
v0.32.0
fixed in 0.52.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39834MEDIUM5.52
golang.org/x/crypto
v0.32.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33809MEDIUM5.52
golang.org/x/image
v0.21.0
fixed in 0.38.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-33813MEDIUM5.52
golang.org/x/image
v0.21.0
fixed in 0.42.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-46599MEDIUM5.52
golang.org/x/image
v0.21.0
fixed in 0.41.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-46601MEDIUM5.52
golang.org/x/image
v0.21.0
fixed in 0.43.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-22872MEDIUM5.52
golang.org/x/net
v0.34.0
fixed in 0.38.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-25680MEDIUM5.52
golang.org/x/net
v0.34.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-47906MEDIUM5.52
stdlib
v1.23.4
fixed in 1.23.12, 1.24.6
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61727MEDIUM5.52
stdlib
v1.23.4
fixed in 1.24.11, 1.25.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39825MEDIUM5.52
stdlib
v1.23.4
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32282MEDIUM5.44
stdlib
v1.23.4
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-12243MEDIUM5.3
gnutls
3.8.8-r0
fixed in 3.8.12-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-32989MEDIUM5.3
gnutls
3.8.8-r0
fixed in 3.8.12-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-59375MEDIUM5.3
libexpat
2.6.4-r0
fixed in 2.7.2-r0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-12133MEDIUM5.3
libtasn1
4.19.0-r2
fixed in 4.20.0-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-33812MEDIUM5.18
golang.org/x/image
v0.21.0
fixed in 0.39.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.34.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32289MEDIUM5.18
stdlib
v1.23.4
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-68121MEDIUM5.1
stdlib
v1.23.4
fixed in 1.24.13, 1.25.7, 1.26.0-rc.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-62408MEDIUM5.02
c-ares
1.34.3-r0
fixed in 1.34.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
libcrypto3
3.3.2-r4
fixed in 3.3.6-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
libcrypto3
3.3.2-r4
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
libcrypto3
3.3.2-r4
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
libcrypto3
3.3.2-r4
fixed in 3.3.6-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-50219MEDIUM5.02
libexpat
2.6.4-r0
fixed in 2.8.2-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-56412MEDIUM5.02
libexpat
2.6.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
libssl3
3.3.2-r4
fixed in 3.3.6-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
libssl3
3.3.2-r4
fixed in 3.3.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
libssl3
3.3.2-r4
fixed in 3.3.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
libssl3
3.3.2-r4
fixed in 3.3.6-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-45336MEDIUM5.02
stdlib
v1.23.4
fixed in 1.22.11, 1.23.5, 1.24.0-rc.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
libcrypto3
3.3.2-r4
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-32776MEDIUM4.67
libexpat
2.6.4-r0
fixed in 2.7.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32777MEDIUM4.67
libexpat
2.6.4-r0
fixed in 2.7.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32778MEDIUM4.67
libexpat
2.6.4-r0
fixed in 2.7.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
libssl3
3.3.2-r4
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-6042MEDIUM4.67
musl
1.2.5-r8
fixed in 1.2.5-r10
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-29088MEDIUM4.67
sqlite-libs
3.47.1-r0
fixed in 3.48.0-r4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2022-31022MEDIUM4.67
github.com/blevesearch/bleve/v2
v2.4.2
fixed in 2.5.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39833MEDIUM4.67
golang.org/x/crypto
v0.32.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32288MEDIUM4.67
stdlib
v1.23.4
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45571MEDIUM4.59
github.com/go-git/go-git/v5
v5.13.1
fixed in 5.19.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.34.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-22871MEDIUM4.59
stdlib
v1.23.4
fixed in 1.23.8, 1.24.2
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
stdlib
v1.23.4
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39823MEDIUM4.59
stdlib
v1.23.4
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.23.4
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-14831MEDIUM4.5
gnutls
3.8.8-r0
fixed in 3.8.12-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42015MEDIUM4.5
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
xz-libs
5.6.3-r0
fixed in 5.8.3-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-68938MEDIUM4.5
code.gitea.io/gitea
1.23.0
fixed in 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69413MEDIUM4.5
code.gitea.io/gitea
1.23.0
fixed in 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58058MEDIUM4.5
github.com/ulikunitz/xz
v0.5.12
fixed in 0.5.15
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47914MEDIUM4.5
golang.org/x/crypto
v0.32.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58181MEDIUM4.5
golang.org/x/crypto
v0.32.0
fixed in 0.45.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-46598MEDIUM4.5
golang.org/x/crypto
v0.32.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47911MEDIUM4.5
golang.org/x/net
v0.34.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58190MEDIUM4.5
golang.org/x/net
v0.34.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-22866MEDIUM4.5
stdlib
v1.23.4
fixed in 1.22.12, 1.23.6, 1.24.0-rc.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-22873MEDIUM4.5
stdlib
v1.23.4
fixed in 1.23.9, 1.24.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-47912MEDIUM4.5
stdlib
v1.23.4
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58185MEDIUM4.5
stdlib
v1.23.4
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58187MEDIUM4.5
stdlib
v1.23.4
fixed in 1.24.9, 1.25.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58188MEDIUM4.5
stdlib
v1.23.4
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58189MEDIUM4.5
stdlib
v1.23.4
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61723MEDIUM4.5
stdlib
v1.23.4
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61724MEDIUM4.5
stdlib
v1.23.4
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61725MEDIUM4.5
stdlib
v1.23.4
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61730MEDIUM4.5
stdlib
v1.23.4
fixed in 1.24.12, 1.25.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42505MEDIUM4.5
stdlib
v1.23.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42507MEDIUM4.5
stdlib
v1.23.4
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58186MEDIUM4.5
stdlib
v1.23.4
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-34165MEDIUM4.25
github.com/go-git/go-git/v5
v5.13.1
fixed in 5.17.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-15467MEDIUM4.06
libcrypto3
3.3.2-r4
fixed in 3.3.6-r0
47.6%
High Exploitation Risk
Post-Exploit
CVE-2025-15467MEDIUM4.06
libssl3
3.3.2-r4
fixed in 3.3.6-r0
47.6%
High Exploitation Risk
Post-Exploit
CVE-2024-13176MEDIUM4
libcrypto3
3.3.2-r4
fixed in 3.3.2-r5
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-68160MEDIUM4
libcrypto3
3.3.2-r4
fixed in 3.3.6-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
libssl3
3.3.2-r4
fixed in 3.3.2-r5
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-68160MEDIUM4
libssl3
3.3.2-r4
fixed in 3.3.6-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-56131LOW3.82
libexpat
2.6.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-22870LOW3.74
golang.org/x/net
v0.34.0
fixed in 0.36.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-22870LOW3.74
stdlib
v1.23.4
fixed in 1.23.7, 1.24.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-25934LOW3.65
github.com/go-git/go-git/v5
v5.13.1
fixed in 5.16.5
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-6965LOW3.61
sqlite-libs
3.47.1-r0
fixed in 3.48.0-r3
74.4%
Actively Exploited
Post-Exploit
CVE-2025-68973LOW3.57
gnupg
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gnupg-dirmngr
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gnupg-gpgconf
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gnupg-keyboxd
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gnupg-utils
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gnupg-wks-client
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gpg
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gpg-agent
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gpg-wks-server
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gpgsm
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gpgv
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2024-45341LOW3.57
stdlib
v1.23.4
fixed in 1.22.11, 1.23.5, 1.24.0-rc.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42010LOW3.53
gnutls
3.8.8-r0
fixed in 3.8.13-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-56171LOW3.53
libxml2
2.13.4-r3
fixed in 2.13.4-r4
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2025-9820LOW3.4
gnutls
3.8.8-r0
fixed in 3.8.12-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW3.4
libcrypto3
3.3.2-r4
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW3.4
libssl3
3.3.2-r4
fixed in 3.3.6-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-49796LOW3.28
libxml2
2.13.4-r3
fixed in 2.13.9-r0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-33186LOW3.28
google.golang.org/grpc
v1.67.1
fixed in 1.79.3
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2025-48386LOW3.21
git
2.47.1-r0
fixed in 2.47.3-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-3832LOW3.15
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-5419LOW3.15
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41080LOW3.15
libexpat
2.6.4-r0
fixed in 2.8.1-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-26958LOW3.15
filippo.io/edwards25519
v1.1.0
fixed in 1.1.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-8556LOW3.15
github.com/cloudflare/circl
v1.5.0
fixed in 1.6.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-29923LOW3.15
github.com/redis/go-redis/v9
v9.7.0
fixed in 9.7.3, 9.6.3, 9.5.5
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-9232LOW3.1
libcrypto3
3.3.2-r4
fixed in 3.3.5-r0
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2025-9232LOW3.1
libssl3
3.3.2-r4
fixed in 3.3.5-r0
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-31789LOW3
libcrypto3
3.3.2-r4
fixed in 3.3.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
libssl3
3.3.2-r4
fixed in 3.3.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-3277LOW3
sqlite-libs
3.47.1-r0
fixed in 3.48.0-r1
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-1229LOW3
github.com/cloudflare/circl
v1.5.0
fixed in 1.6.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-0798LOW2.98
code.gitea.io/gitea
1.23.0
fixed in 1.25.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-32988LOW2.95
gnutls
3.8.8-r0
fixed in 3.8.12-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2025-48384LOW2.88
git
2.47.1-r0
fixed in 2.47.3-r0
2.8%
Low-Moderate Risk
Post-Exploit
CVE-2026-33845LOW2.78
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-49794LOW2.78
libxml2
2.13.4-r3
fixed in 2.13.9-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2024-52006LOW2.7
git
2.47.1-r0
fixed in 2.47.2-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2024-8176LOW2.7
libexpat
2.6.4-r0
fixed in 2.7.0-r0
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2025-27113LOW2.7
libxml2
2.13.4-r3
fixed in 2.13.4-r5
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2025-6021LOW2.7
libxml2
2.13.4-r3
fixed in 2.13.9-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2025-5399LOW2.58
curl
8.11.1-r0
fixed in 8.14.1-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-5399LOW2.58
libcurl
8.11.1-r0
fixed in 8.14.1-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-48385LOW2.54
git
2.47.1-r0
fixed in 2.47.3-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-5025LOW2.45
curl
8.11.1-r0
fixed in 8.14.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-10148LOW2.45
curl
8.11.1-r0
fixed in 8.14.1-r2
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-5025LOW2.45
libcurl
8.11.1-r0
fixed in 8.14.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-10148LOW2.45
libcurl
8.11.1-r0
fixed in 8.14.1-r2
0.5%
Theoretical Threat
Post-Exploit
CVE-2024-50349LOW2.4
git
2.47.1-r0
fixed in 2.47.2-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gnupg
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gnupg-dirmngr
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gnupg-gpgconf
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gnupg-keyboxd
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gnupg-utils
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gnupg-wks-client
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gpg
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gpg-agent
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gpg-wks-server
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gpgsm
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gpgv
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-0665LOW2.4
curl
8.11.1-r0
fixed in 8.12.0-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-0725LOW2.4
curl
8.11.1-r0
fixed in 8.12.0-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2025-0665LOW2.4
libcurl
8.11.1-r0
fixed in 8.12.0-r0
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-0725LOW2.4
libcurl
8.11.1-r0
fixed in 8.12.0-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-33762LOW2.38
github.com/go-git/go-git/v5
v5.13.1
fixed in 5.17.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-27613LOW2.19
git
2.47.1-r0
fixed in 2.47.3-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-24515LOW2.12
libexpat
2.6.4-r0
fixed in 2.7.4-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-6170LOW2.12
libxml2
2.13.4-r3
fixed in 2.13.9-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27139LOW2.12
stdlib
v1.23.4
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-4947LOW1.99
curl
8.11.1-r0
fixed in 8.14.0-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-4947LOW1.99
libcurl
8.11.1-r0
fixed in 8.14.0-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-27614LOW1.93
git
2.47.1-r0
fixed in 2.47.3-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-9086LOW1.91
curl
8.11.1-r0
fixed in 8.14.1-r2
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-9086LOW1.91
libcurl
8.11.1-r0
fixed in 8.14.1-r2
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-46394LOW1.68
busybox
1.37.0-r9
fixed in 1.37.0-r14
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-46394LOW1.68
busybox-binsh
1.37.0-r9
fixed in 1.37.0-r14
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-46394LOW1.68
ssl_client
1.37.0-r9
fixed in 1.37.0-r14
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-46835LOW1.58
git
2.47.1-r0
fixed in 2.47.3-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-48385NONE0
git-init-template
2.47.1-r0
fixed in 2.47.3-r0
0.8%
Theoretical Threat
Not Applicable
CVE-2025-48384NONE0
git-init-template
2.47.1-r0
fixed in 2.47.3-r0
2.8%
Low-Moderate Risk
Not Applicable
CVE-2026-40200NONE0
musl-utils
1.2.5-r8
fixed in 1.2.5-r11
0.2%
Theoretical Threat
Not Applicable
CVE-2024-52006NONE0
git-init-template
2.47.1-r0
fixed in 2.47.2-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2025-26519NONE0
musl-utils
1.2.5-r8
fixed in 1.2.5-r9
0.3%
Theoretical Threat
Not Applicable
CVE-2025-27614NONE0
git-init-template
2.47.1-r0
fixed in 2.47.3-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2025-48386NONE0
git-init-template
2.47.1-r0
fixed in 2.47.3-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-6042NONE0
musl-utils
1.2.5-r8
fixed in 1.2.5-r10
0.2%
Theoretical Threat
Not Applicable
CVE-2024-50349NONE0
git-init-template
2.47.1-r0
fixed in 2.47.2-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2025-27613NONE0
git-init-template
2.47.1-r0
fixed in 2.47.3-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2025-46835NONE0
git-init-template
2.47.1-r0
fixed in 2.47.3-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
busybox
1.37.0-r9
fixed in 1.37.0-r14
0.2%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
busybox-binsh
1.37.0-r9
fixed in 1.37.0-r14
0.2%
Theoretical Threat
Not Applicable
CVE-2025-0167NONE0
curl
8.11.1-r0
fixed in 8.12.0-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2025-46334NONE0
git
2.47.1-r0
fixed in 2.47.3-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2025-46334NONE0
git-init-template
2.47.1-r0
fixed in 2.47.3-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2025-0167NONE0
libcurl
8.11.1-r0
fixed in 8.12.0-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-56408NONE0
libexpat
2.6.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56409NONE0
libexpat
2.6.4-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
ssl_client
1.37.0-r9
fixed in 1.37.0-r14
0.2%
Theoretical Threat
Not Applicable
CVE-2026-20896NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.3
31.8%
High Exploitation Risk
Not Applicable
CVE-2026-22874NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-56750NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-58426NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.2
0.2%
Theoretical Threat
Not Applicable
CVE-2026-58443NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-20779NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-22555NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-24451NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-24791NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.2
Not Applicable
CVE-2026-25038NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-26231NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-27771NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.2
43.1%
High Exploitation Risk
Not Applicable
CVE-2026-27775NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-28699NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.2
0.6%
Theoretical Threat
Not Applicable
CVE-2026-28744NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-54481NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-55987NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-56654NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-56755NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-57894NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-58314NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-58419NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58421NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58422NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58423NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58424NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.3
0.2%
Theoretical Threat
Not Applicable
CVE-2026-58436NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-58437NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-20706NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.2
0.5%
Theoretical Threat
Not Applicable
CVE-2026-25714NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-27761NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27783NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42931NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-50105NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-55982NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-56443NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-56657NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-57886NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-57897NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-58418NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-58425NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-58428NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-58429NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-58432NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-58435NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-58441NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-58442NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-58444NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-58507NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-58510NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-59763NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-59765NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-59766NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
GHSA-3m6q-h5gj-7mrwNONE0
code.gitea.io/gitea
1.23.0
fixed in 1.25.0
Not Applicable
GHSA-rjvx-x5h2-6px5NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.26.0
Not Applicable
CVE-2026-23603NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-55984NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-58434NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-58445NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
CVE-2026-58511NONE0
code.gitea.io/gitea
1.23.0
fixed in 1.27.0
Not Applicable
GHSA-vrw8-fxc6-2r93NONE0
github.com/go-chi/chi/v5
v5.1.0
fixed in 5.2.2
Not Applicable
GHSA-w5pp-99ch-qj29NONE0
github.com/go-git/go-git/v5
v5.13.1
fixed in 5.19.1
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.32.0
No fix yet
Not Applicable
CVE-2026-46602NONE0
golang.org/x/image
v0.21.0
fixed in 0.43.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-46604NONE0
golang.org/x/image
v0.21.0
fixed in 0.43.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42500NONE0
golang.org/x/image
v0.21.0
fixed in 0.41.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.34.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.29.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.21.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.67.1
fixed in 1.82.1
Not Applicable
CVE-2025-0913NONE0
stdlib
v1.23.4
fixed in 1.23.10, 1.24.4
0.2%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.