Vulnerability Reportgitea/gitea:1.24.2-rootless

gitea/gitea:1.24.2-rootless
digestsha256:78eccee0e28d618a2683d4ed348374395db26c363fa111d7e42694bcaf0a4d65

Executive Summary

Last scanned:

Threat Score
74/100CAUTION
Reputation
RELIABLE

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could crash the Git service or corrupt memory via crafted network traffic, leveraging remote denial-of-service vulnerabilities like CVE-2026-33630 and CVE-2026-1584. However, the OpenSSL CVE-2026-28388 only triggers under non-default delta CRL processing, which Gitea does not use in normal operations. Restricting network exposure and applying vendor patches are essential to reduce risk to an acceptable level.

Vulnerabilities

Vulnerability Log

346 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-33630HIGH7.5
c-ares
1.34.5-r0
fixed in 1.34.8-r0
Directly Exposed
CVE-2026-1584HIGH7.5
gnutls
3.8.8-r0
fixed in 3.8.12-r0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-33846HIGH7.5
gnutls
3.8.8-r0
fixed in 3.8.13-r0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-42009HIGH7.5
gnutls
3.8.8-r0
fixed in 3.8.13-r0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-28388HIGH7.5
libcrypto3
3.5.0-r0
fixed in 3.5.6-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-28389HIGH7.5
libcrypto3
3.5.0-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-28390HIGH7.5
libcrypto3
3.5.0-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-34183HIGH7.5
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-28388HIGH7.5
libssl3
3.5.0-r0
fixed in 3.5.6-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-28389HIGH7.5
libssl3
3.5.0-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-28390HIGH7.5
libssl3
3.5.0-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-34183HIGH7.5
libssl3
3.5.0-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-6021HIGH7.5
libxml2
2.13.8-r0
fixed in 2.13.9-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-2100HIGH7.5
p11-kit
0.25.5-r2
fixed in 0.26.2-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-32952HIGH7.5
github.com/Azure/go-ntlmssp
v0.0.0-20221128193559-754e69321358
fixed in 0.1.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-61726HIGH7.5
stdlib
v1.24.4
fixed in 1.24.12, 1.25.6
1.9%
Low-Moderate Risk
Directly Exposed
CVE-2026-39828HIGH7.48
golang.org/x/crypto
v0.37.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39832HIGH7.39
golang.org/x/crypto
v0.37.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-32990MEDIUM6.97
gnutls
3.8.8-r0
fixed in 3.8.12-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42013MEDIUM6.97
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5260MEDIUM6.97
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-39821MEDIUM6.97
golang.org/x/net
v0.39.0
fixed in 0.55.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM6.88
libcrypto3
3.5.0-r0
fixed in 3.5.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM6.88
libssl3
3.5.0-r0
fixed in 3.5.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-44973MEDIUM6.88
github.com/go-git/go-billy/v5
v5.6.2
fixed in 5.9.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39831MEDIUM6.88
golang.org/x/crypto
v0.37.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-25681MEDIUM6.88
golang.org/x/net
v0.39.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27136MEDIUM6.88
golang.org/x/net
v0.39.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-68121MEDIUM6.8
stdlib
v1.24.4
fixed in 1.24.13, 1.25.7, 1.26.0-rc.3
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-25210MEDIUM6.63
libexpat
2.7.1-r0
fixed in 2.7.4-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40200MEDIUM6.63
musl
1.2.5-r10
fixed in 1.2.5-r12
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22184MEDIUM6.63
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39822MEDIUM6.63
stdlib
v1.24.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69421MEDIUM6.38
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-45186MEDIUM6.38
libexpat
2.7.1-r0
fixed in 2.8.1-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69421MEDIUM6.38
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-49795MEDIUM6.38
libxml2
2.13.8-r0
fixed in 2.13.9-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-6732MEDIUM6.38
libxml2
2.13.8-r0
fixed in 2.13.9-r1
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-27135MEDIUM6.38
nghttp2-libs
1.65.0-r0
fixed in 1.68.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-20736MEDIUM6.38
code.gitea.io/gitea
v1.24.2
fixed in 1.25.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-44740MEDIUM6.38
github.com/go-git/go-billy/v5
v5.6.2
fixed in 5.9.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45022MEDIUM6.38
github.com/go-git/go-git/v5
v5.16.0
fixed in 5.19.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-47913MEDIUM6.38
golang.org/x/crypto
v0.37.0
fixed in 0.43.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39829MEDIUM6.38
golang.org/x/crypto
v0.37.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-39830MEDIUM6.38
golang.org/x/crypto
v0.37.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39835MEDIUM6.38
golang.org/x/crypto
v0.37.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-46597MEDIUM6.38
golang.org/x/crypto
v0.37.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
golang.org/x/net
v0.39.0
fixed in 0.53.0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-61729MEDIUM6.38
stdlib
v1.24.4
fixed in 1.24.11, 1.25.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-25679MEDIUM6.38
stdlib
v1.24.4
fixed in 1.25.8, 1.26.1
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-27145MEDIUM6.38
stdlib
v1.24.4
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-32280MEDIUM6.38
stdlib
v1.24.4
fixed in 1.25.9, 1.26.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-32281MEDIUM6.38
stdlib
v1.24.4
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32283MEDIUM6.38
stdlib
v1.24.4
fixed in 1.25.9, 1.26.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33811MEDIUM6.38
stdlib
v1.24.4
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
stdlib
v1.24.4
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-39820MEDIUM6.38
stdlib
v1.24.4
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-39836MEDIUM6.38
stdlib
v1.24.4
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42499MEDIUM6.38
stdlib
v1.24.4
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-42504MEDIUM6.38
stdlib
v1.24.4
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-58183MEDIUM6.38
stdlib
v1.24.4
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61728MEDIUM6.38
stdlib
v1.24.4
fixed in 1.24.12, 1.25.6
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-3833MEDIUM6.29
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42011MEDIUM6.29
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-69419MEDIUM6.29
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69419MEDIUM6.29
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41506MEDIUM6.29
github.com/go-git/go-git/v5
v5.16.0
fixed in 5.18.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42508MEDIUM6.29
golang.org/x/crypto
v0.37.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-11187MEDIUM6.1
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2025-11187MEDIUM6.1
libssl3
3.5.0-r0
fixed in 3.5.5-r0
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2026-42012MEDIUM6.03
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-46595MEDIUM6.03
golang.org/x/crypto
v0.37.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-47907MEDIUM5.95
stdlib
v1.24.4
fixed in 1.23.12, 1.24.6
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-9231MEDIUM5.9
libcrypto3
3.5.0-r0
fixed in 3.5.4-r0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-31790MEDIUM5.9
libcrypto3
3.5.0-r0
fixed in 3.5.6-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-42764MEDIUM5.9
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-9231MEDIUM5.9
libssl3
3.5.0-r0
fixed in 3.5.4-r0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-31790MEDIUM5.9
libssl3
3.5.0-r0
fixed in 3.5.6-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-42764MEDIUM5.9
libssl3
3.5.0-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-13151MEDIUM5.9
libtasn1
4.20.0-r0
fixed in 4.21.0-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-56132MEDIUM5.87
libexpat
2.7.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56403MEDIUM5.87
libexpat
2.7.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56404MEDIUM5.87
libexpat
2.7.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56405MEDIUM5.87
libexpat
2.7.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56406MEDIUM5.87
libexpat
2.7.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56407MEDIUM5.87
libexpat
2.7.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56410MEDIUM5.87
libexpat
2.7.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56411MEDIUM5.87
libexpat
2.7.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42014MEDIUM5.61
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-9230MEDIUM5.6
libcrypto3
3.5.0-r0
fixed in 3.5.4-r0
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2025-9230MEDIUM5.6
libssl3
3.5.0-r0
fixed in 3.5.4-r0
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2025-6395MEDIUM5.52
gnutls
3.8.8-r0
fixed in 3.8.12-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
libcrypto3
3.5.0-r0
fixed in 3.5.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
libssl3
3.5.0-r0
fixed in 3.5.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-11579MEDIUM5.52
github.com/nwaples/rardecode
v1.1.3
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39827MEDIUM5.52
golang.org/x/crypto
v0.37.0
fixed in 0.52.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39834MEDIUM5.52
golang.org/x/crypto
v0.37.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33809MEDIUM5.52
golang.org/x/image
v0.26.0
fixed in 0.38.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-33813MEDIUM5.52
golang.org/x/image
v0.26.0
fixed in 0.42.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-46599MEDIUM5.52
golang.org/x/image
v0.26.0
fixed in 0.41.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-46601MEDIUM5.52
golang.org/x/image
v0.26.0
fixed in 0.43.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-25680MEDIUM5.52
golang.org/x/net
v0.39.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-47906MEDIUM5.52
stdlib
v1.24.4
fixed in 1.23.12, 1.24.6
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61727MEDIUM5.52
stdlib
v1.24.4
fixed in 1.24.11, 1.25.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39825MEDIUM5.52
stdlib
v1.24.4
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32282MEDIUM5.44
stdlib
v1.24.4
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-12243MEDIUM5.3
gnutls
3.8.8-r0
fixed in 3.8.12-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-32989MEDIUM5.3
gnutls
3.8.8-r0
fixed in 3.8.12-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-59375MEDIUM5.3
libexpat
2.7.1-r0
fixed in 2.7.2-r0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-33812MEDIUM5.18
golang.org/x/image
v0.26.0
fixed in 0.39.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.39.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32289MEDIUM5.18
stdlib
v1.24.4
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-62408MEDIUM5.02
c-ares
1.34.5-r0
fixed in 1.34.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-50219MEDIUM5.02
libexpat
2.7.1-r0
fixed in 2.8.2-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-56412MEDIUM5.02
libexpat
2.7.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM5
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-34180MEDIUM5
libssl3
3.5.0-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-15469MEDIUM4.67
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-32776MEDIUM4.67
libexpat
2.7.1-r0
fixed in 2.7.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32777MEDIUM4.67
libexpat
2.7.1-r0
fixed in 2.7.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32778MEDIUM4.67
libexpat
2.7.1-r0
fixed in 2.7.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-15469MEDIUM4.67
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-6042MEDIUM4.67
musl
1.2.5-r10
fixed in 1.2.5-r11
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-39833MEDIUM4.67
golang.org/x/crypto
v0.37.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32288MEDIUM4.67
stdlib
v1.24.4
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45571MEDIUM4.59
github.com/go-git/go-git/v5
v5.16.0
fixed in 5.19.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.39.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
stdlib
v1.24.4
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39823MEDIUM4.59
stdlib
v1.24.4
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.24.4
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-14831MEDIUM4.5
gnutls
3.8.8-r0
fixed in 3.8.12-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42015MEDIUM4.5
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libssl3
3.5.0-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
xz-libs
5.8.1-r0
fixed in 5.8.3-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-68938MEDIUM4.5
code.gitea.io/gitea
v1.24.2
fixed in 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69413MEDIUM4.5
code.gitea.io/gitea
v1.24.2
fixed in 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58058MEDIUM4.5
github.com/ulikunitz/xz
v0.5.12
fixed in 0.5.15
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47914MEDIUM4.5
golang.org/x/crypto
v0.37.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58181MEDIUM4.5
golang.org/x/crypto
v0.37.0
fixed in 0.45.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-46598MEDIUM4.5
golang.org/x/crypto
v0.37.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47911MEDIUM4.5
golang.org/x/net
v0.39.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58190MEDIUM4.5
golang.org/x/net
v0.39.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-47912MEDIUM4.5
stdlib
v1.24.4
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58185MEDIUM4.5
stdlib
v1.24.4
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58187MEDIUM4.5
stdlib
v1.24.4
fixed in 1.24.9, 1.25.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58188MEDIUM4.5
stdlib
v1.24.4
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58189MEDIUM4.5
stdlib
v1.24.4
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61723MEDIUM4.5
stdlib
v1.24.4
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61724MEDIUM4.5
stdlib
v1.24.4
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61725MEDIUM4.5
stdlib
v1.24.4
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61730MEDIUM4.5
stdlib
v1.24.4
fixed in 1.24.12, 1.25.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42505MEDIUM4.5
stdlib
v1.24.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42507MEDIUM4.5
stdlib
v1.24.4
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58186MEDIUM4.5
stdlib
v1.24.4
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-34165MEDIUM4.25
github.com/go-git/go-git/v5
v5.16.0
fixed in 5.17.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-15467MEDIUM4.06
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
47.6%
High Exploitation Risk
Post-Exploit
CVE-2025-15467MEDIUM4.06
libssl3
3.5.0-r0
fixed in 3.5.5-r0
47.6%
High Exploitation Risk
Post-Exploit
CVE-2025-68160MEDIUM4
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-68160MEDIUM4
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69725MEDIUM4
github.com/go-chi/chi/v5
v5.2.2
fixed in 5.2.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-56131LOW3.82
libexpat
2.7.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-25934LOW3.65
github.com/go-git/go-git/v5
v5.16.0
fixed in 5.16.5
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-6965LOW3.61
sqlite-libs
3.49.2-r0
fixed in 3.49.2-r1
74.4%
Actively Exploited
Post-Exploit
CVE-2025-68973LOW3.57
gnupg
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gnupg-gpgconf
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gnupg-utils
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gnupg-wks-client
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gpg
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gpg-agent
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gpgsm
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gpgv
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-42010LOW3.53
gnutls
3.8.8-r0
fixed in 3.8.13-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2025-9820LOW3.4
gnutls
3.8.8-r0
fixed in 3.8.12-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW3.4
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW3.4
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-49796LOW3.28
libxml2
2.13.8-r0
fixed in 2.13.9-r0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-33186LOW3.28
google.golang.org/grpc
v1.72.0
fixed in 1.79.3
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2025-48386LOW3.21
git
2.49.0-r0
fixed in 2.49.1-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-3832LOW3.15
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-5419LOW3.15
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41080LOW3.15
libexpat
2.7.1-r0
fixed in 2.8.1-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-26958LOW3.15
filippo.io/edwards25519
v1.1.0
fixed in 1.1.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-9232LOW3.1
libcrypto3
3.5.0-r0
fixed in 3.5.4-r0
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2025-9232LOW3.1
libssl3
3.5.0-r0
fixed in 3.5.4-r0
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-31789LOW3
libcrypto3
3.5.0-r0
fixed in 3.5.6-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
libssl3
3.5.0-r0
fixed in 3.5.6-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-1229LOW3
github.com/cloudflare/circl
v1.6.1
fixed in 1.6.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-0798LOW2.98
code.gitea.io/gitea
v1.24.2
fixed in 1.25.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-32988LOW2.95
gnutls
3.8.8-r0
fixed in 3.8.12-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-45570LOW2.94
github.com/go-git/go-git/v5
v5.16.0
fixed in 5.19.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
libssl3
3.5.0-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2025-48384LOW2.88
git
2.49.0-r0
fixed in 2.49.1-r0
2.8%
Low-Moderate Risk
Post-Exploit
CVE-2026-33845LOW2.78
gnutls
3.8.8-r0
fixed in 3.8.13-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-49794LOW2.78
libxml2
2.13.8-r0
fixed in 2.13.9-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-58050LOW2.78
pcre2
10.43-r1
fixed in 10.46-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-59937LOW2.78
github.com/wneessen/go-mail
v0.6.2
fixed in 0.7.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-48385LOW2.54
git
2.49.0-r0
fixed in 2.49.1-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-10148LOW2.45
curl
8.14.1-r0
fixed in 8.14.1-r2
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-10148LOW2.45
libcurl
8.14.1-r0
fixed in 8.14.1-r2
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gnupg
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gnupg-gpgconf
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gnupg-utils
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gnupg-wks-client
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gpg
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gpg-agent
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gpgsm
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gpgv
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-33762LOW2.38
github.com/go-git/go-git/v5
v5.16.0
fixed in 5.17.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-27613LOW2.19
git
2.49.0-r0
fixed in 2.49.1-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-24515LOW2.12
libexpat
2.7.1-r0
fixed in 2.7.4-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-6170LOW2.12
libxml2
2.13.8-r0
fixed in 2.13.9-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27139LOW2.12
stdlib
v1.24.4
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5545LOW1.99
curl
8.14.1-r0
fixed in 8.14.1-r3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW1.99
libcurl
8.14.1-r0
fixed in 8.14.1-r3
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-27614LOW1.93
git
2.49.0-r0
fixed in 2.49.1-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-9086LOW1.91
curl
8.14.1-r0
fixed in 8.14.1-r2
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-9086LOW1.91
libcurl
8.14.1-r0
fixed in 8.14.1-r2
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-46394LOW1.68
busybox
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-46394LOW1.68
busybox-binsh
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-46394LOW1.68
ssl_client
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-46835LOW1.58
git
2.49.0-r0
fixed in 2.49.1-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-48385NONE0
git-init-template
2.49.0-r0
fixed in 2.49.1-r0
0.8%
Theoretical Threat
Not Applicable
CVE-2025-48384NONE0
git-init-template
2.49.0-r0
fixed in 2.49.1-r0
2.8%
Low-Moderate Risk
Not Applicable
CVE-2026-40200NONE0
musl-utils
1.2.5-r10
fixed in 1.2.5-r12
0.2%
Theoretical Threat
Not Applicable
CVE-2025-68973NONE0
gnupg-dirmngr
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2025-68973NONE0
gnupg-keyboxd
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2025-68973NONE0
gpg-wks-server
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2025-27614NONE0
git-init-template
2.49.0-r0
fixed in 2.49.1-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2025-48386NONE0
git-init-template
2.49.0-r0
fixed in 2.49.1-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-6042NONE0
musl-utils
1.2.5-r10
fixed in 1.2.5-r11
0.2%
Theoretical Threat
Not Applicable
CVE-2025-68972NONE0
gnupg-dirmngr
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2025-68972NONE0
gnupg-keyboxd
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2025-68972NONE0
gpg-wks-server
2.4.7-r0
fixed in 2.4.9-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2025-27613NONE0
git-init-template
2.49.0-r0
fixed in 2.49.1-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2025-46835NONE0
git-init-template
2.49.0-r0
fixed in 2.49.1-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
busybox
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
busybox-binsh
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Not Applicable
CVE-2025-46334NONE0
git
2.49.0-r0
fixed in 2.49.1-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2025-46334NONE0
git-init-template
2.49.0-r0
fixed in 2.49.1-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2025-4575NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.1-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-56408NONE0
libexpat
2.7.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56409NONE0
libexpat
2.7.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2025-4575NONE0
libssl3
3.5.0-r0
fixed in 3.5.1-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
ssl_client
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Not Applicable
CVE-2026-20896NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.3
31.8%
High Exploitation Risk
Not Applicable
CVE-2026-22874NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-56750NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-58426NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.2
0.2%
Theoretical Threat
Not Applicable
CVE-2026-58443NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-20779NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-22555NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-24451NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-24791NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.2
Not Applicable
CVE-2026-25038NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-26231NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-27771NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.2
43.1%
High Exploitation Risk
Not Applicable
CVE-2026-27775NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-28699NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.2
0.6%
Theoretical Threat
Not Applicable
CVE-2026-28744NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-54481NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-55987NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-56654NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-56755NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-57894NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-58314NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-58419NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58421NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58422NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58423NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58424NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.3
0.2%
Theoretical Threat
Not Applicable
CVE-2026-58436NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-58437NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-20706NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.2
0.5%
Theoretical Threat
Not Applicable
CVE-2026-25714NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-27761NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27783NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42931NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-50105NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-55982NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-56443NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-56657NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-57886NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-57897NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-58418NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-58425NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-58428NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-58429NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-58432NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-58435NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-58441NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-58442NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-58444NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-58507NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-58510NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-59763NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-59765NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-59766NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
GHSA-3m6q-h5gj-7mrwNONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.25.0
Not Applicable
GHSA-rjvx-x5h2-6px5NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.26.0
Not Applicable
CVE-2026-23603NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-55984NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-58434NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-58445NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
CVE-2026-58511NONE0
code.gitea.io/gitea
v1.24.2
fixed in 1.27.0
Not Applicable
GHSA-w5pp-99ch-qj29NONE0
github.com/go-git/go-git/v5
v5.16.0
fixed in 5.19.1
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.37.0
No fix yet
Not Applicable
CVE-2026-46602NONE0
golang.org/x/image
v0.26.0
fixed in 0.43.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-46604NONE0
golang.org/x/image
v0.26.0
fixed in 0.43.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42500NONE0
golang.org/x/image
v0.26.0
fixed in 0.41.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.39.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.32.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.24.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.72.0
fixed in 1.82.1
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.