Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could remotely crash the service or cause memory exhaustion by exploiting denial-of-service flaws in GnuTLS and OpenSSL (e.g., CVE-2026-33846, CVE-2026-34183). The exposure is broad, with 13 exposed findings rated at severity 7.0 or higher, and a maximum severity of 7.5. Note that some OpenSSL CMS vulnerabilities require processing of untrusted CMS data, which is not a standard Gitea operation, reducing their practical impact.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-33630 | HIGH7.5 | c-ares 1.34.5-r0 fixed in 1.34.8-r0 | — | Directly Exposed |
| CVE-2026-33846 | HIGH7.5 | gnutls 3.8.8-r0 fixed in 3.8.13-r0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42009 | HIGH7.5 | gnutls 3.8.8-r0 fixed in 3.8.13-r0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28389 | HIGH7.5 | libcrypto3 3.5.4-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28390 | HIGH7.5 | libcrypto3 3.5.4-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-34183 | HIGH7.5 | libcrypto3 3.5.4-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28389 | HIGH7.5 | libssl3 3.5.4-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28390 | HIGH7.5 | libssl3 3.5.4-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-34183 | HIGH7.5 | libssl3 3.5.4-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-32952 | HIGH7.5 | github.com/Azure/go-ntlmssp v0.0.0-20221128193559-754e69321358 fixed in 0.1.1 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-61726 | HIGH7.5 | stdlib v1.25.3 fixed in 1.24.12, 1.25.6 | 1.9% Low-Moderate Risk | Directly ExposedContext importance: HIGH |
| CVE-2026-39828 | HIGH7.48 | golang.org/x/crypto v0.42.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-39832 | HIGH7.39 | golang.org/x/crypto v0.42.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-32990 | MEDIUM6.97 | gnutls 3.8.8-r0 fixed in 3.8.12-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-42013 | MEDIUM6.97 | gnutls 3.8.8-r0 fixed in 3.8.13-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5260 | MEDIUM6.97 | gnutls 3.8.8-r0 fixed in 3.8.13-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-39821 | MEDIUM6.97 | golang.org/x/net v0.44.0 fixed in 0.55.0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM6.88 | libcrypto3 3.5.4-r0 fixed in 3.5.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM6.88 | libssl3 3.5.4-r0 fixed in 3.5.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-44973 | MEDIUM6.88 | github.com/go-git/go-billy/v5 v5.6.2 fixed in 5.9.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39831 | MEDIUM6.88 | golang.org/x/crypto v0.42.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-25681 | MEDIUM6.88 | golang.org/x/net v0.44.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27136 | MEDIUM6.88 | golang.org/x/net v0.44.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-25210 | MEDIUM6.63 | libexpat 2.7.3-r0 fixed in 2.7.4-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40200 | MEDIUM6.63 | musl 1.2.5-r10 fixed in 1.2.5-r12 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40200 | MEDIUM6.63 | musl-utils 1.2.5-r10 fixed in 1.2.5-r12 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-22184 | MEDIUM6.63 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-39822 | MEDIUM6.63 | stdlib v1.25.3 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-45570 | MEDIUM6.53 | github.com/go-git/go-git/v5 v5.16.3 fixed in 5.19.1 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2025-69421 | MEDIUM6.38 | libcrypto3 3.5.4-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-45186 | MEDIUM6.38 | libexpat 2.7.3-r0 fixed in 2.8.1-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | MEDIUM6.38 | libssl3 3.5.4-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-6732 | MEDIUM6.38 | libxml2 2.13.9-r0 fixed in 2.13.9-r1 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-27135 | MEDIUM6.38 | nghttp2-libs 1.65.0-r0 fixed in 1.68.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-20736 | MEDIUM6.38 | code.gitea.io/gitea v1.25.1 fixed in 1.25.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-44740 | MEDIUM6.38 | github.com/go-git/go-billy/v5 v5.6.2 fixed in 5.9.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-45022 | MEDIUM6.38 | github.com/go-git/go-git/v5 v5.16.3 fixed in 5.19.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-47913 | MEDIUM6.38 | golang.org/x/crypto v0.42.0 fixed in 0.43.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-39829 | MEDIUM6.38 | golang.org/x/crypto v0.42.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-39830 | MEDIUM6.38 | golang.org/x/crypto v0.42.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-39835 | MEDIUM6.38 | golang.org/x/crypto v0.42.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-46597 | MEDIUM6.38 | golang.org/x/crypto v0.42.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-33814 | MEDIUM6.38 | golang.org/x/net v0.44.0 fixed in 0.53.0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-61729 | MEDIUM6.38 | stdlib v1.25.3 fixed in 1.24.11, 1.25.5 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-25679 | MEDIUM6.38 | stdlib v1.25.3 fixed in 1.25.8, 1.26.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-27145 | MEDIUM6.38 | stdlib v1.25.3 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-32280 | MEDIUM6.38 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-32281 | MEDIUM6.38 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-32283 | MEDIUM6.38 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-33811 | MEDIUM6.38 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-33814 | MEDIUM6.38 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-39820 | MEDIUM6.38 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-39836 | MEDIUM6.38 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42499 | MEDIUM6.38 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-42504 | MEDIUM6.38 | stdlib v1.25.3 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-61728 | MEDIUM6.38 | stdlib v1.25.3 fixed in 1.24.12, 1.25.6 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-3833 | MEDIUM6.29 | gnutls 3.8.8-r0 fixed in 3.8.13-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42011 | MEDIUM6.29 | gnutls 3.8.8-r0 fixed in 3.8.13-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | MEDIUM6.29 | libcrypto3 3.5.4-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34182 | MEDIUM6.29 | libcrypto3 3.5.4-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | MEDIUM6.29 | libssl3 3.5.4-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34182 | MEDIUM6.29 | libssl3 3.5.4-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-41506 | MEDIUM6.29 | github.com/go-git/go-git/v5 v5.16.3 fixed in 5.18.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42508 | MEDIUM6.29 | golang.org/x/crypto v0.42.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-11187 | MEDIUM6.1 | libcrypto3 3.5.4-r0 fixed in 3.5.5-r0 | 4.5% Low-Moderate Risk | Directly Exposed |
| CVE-2025-11187 | MEDIUM6.1 | libssl3 3.5.4-r0 fixed in 3.5.5-r0 | 4.5% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42012 | MEDIUM6.03 | gnutls 3.8.8-r0 fixed in 3.8.13-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-46595 | MEDIUM6.03 | golang.org/x/crypto v0.42.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libcrypto3 3.5.4-r0 fixed in 3.5.6-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42764 | MEDIUM5.9 | libcrypto3 3.5.4-r0 fixed in 3.5.7-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libssl3 3.5.4-r0 fixed in 3.5.6-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42764 | MEDIUM5.9 | libssl3 3.5.4-r0 fixed in 3.5.7-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-13151 | MEDIUM5.9 | libtasn1 4.20.0-r0 fixed in 4.21.0-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-56132 | MEDIUM5.87 | libexpat 2.7.3-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56403 | MEDIUM5.87 | libexpat 2.7.3-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56404 | MEDIUM5.87 | libexpat 2.7.3-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56405 | MEDIUM5.87 | libexpat 2.7.3-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56406 | MEDIUM5.87 | libexpat 2.7.3-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56407 | MEDIUM5.87 | libexpat 2.7.3-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56410 | MEDIUM5.87 | libexpat 2.7.3-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56411 | MEDIUM5.87 | libexpat 2.7.3-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-42014 | MEDIUM5.61 | gnutls 3.8.8-r0 fixed in 3.8.13-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-6395 | MEDIUM5.52 | gnutls 3.8.8-r0 fixed in 3.8.12-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-2673 | MEDIUM5.52 | libcrypto3 3.5.4-r0 fixed in 3.5.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-2673 | MEDIUM5.52 | libssl3 3.5.4-r0 fixed in 3.5.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-39827 | MEDIUM5.52 | golang.org/x/crypto v0.42.0 fixed in 0.52.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39834 | MEDIUM5.52 | golang.org/x/crypto v0.42.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-33809 | MEDIUM5.52 | golang.org/x/image v0.30.0 fixed in 0.38.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-33813 | MEDIUM5.52 | golang.org/x/image v0.30.0 fixed in 0.42.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-46599 | MEDIUM5.52 | golang.org/x/image v0.30.0 fixed in 0.41.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-46601 | MEDIUM5.52 | golang.org/x/image v0.30.0 fixed in 0.43.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-25680 | MEDIUM5.52 | golang.org/x/net v0.44.0 fixed in 0.55.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-61727 | MEDIUM5.52 | stdlib v1.25.3 fixed in 1.24.11, 1.25.5 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39825 | MEDIUM5.52 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-32282 | MEDIUM5.44 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-34181 | MEDIUM5.35 | libcrypto3 3.5.4-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42768 | MEDIUM5.35 | libcrypto3 3.5.4-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-34181 | MEDIUM5.35 | libssl3 3.5.4-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42768 | MEDIUM5.35 | libssl3 3.5.4-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-12243 | MEDIUM5.3 | gnutls 3.8.8-r0 fixed in 3.8.12-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-32989 | MEDIUM5.3 | gnutls 3.8.8-r0 fixed in 3.8.12-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33812 | MEDIUM5.18 | golang.org/x/image v0.30.0 fixed in 0.39.0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-42502 | MEDIUM5.18 | golang.org/x/net v0.44.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32289 | MEDIUM5.18 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-68121 | MEDIUM5.1 | stdlib v1.25.3 fixed in 1.24.13, 1.25.7, 1.26.0-rc.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-62408 | MEDIUM5.02 | c-ares 1.34.5-r0 fixed in 1.34.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-15468 | MEDIUM5.02 | libcrypto3 3.5.4-r0 fixed in 3.5.5-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libcrypto3 3.5.4-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libcrypto3 3.5.4-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libcrypto3 3.5.4-r0 fixed in 3.5.5-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42769 | MEDIUM5.02 | libcrypto3 3.5.4-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42770 | MEDIUM5.02 | libcrypto3 3.5.4-r0 fixed in 3.5.7-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libcrypto3 3.5.4-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-50219 | MEDIUM5.02 | libexpat 2.7.3-r0 fixed in 2.8.2-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-56412 | MEDIUM5.02 | libexpat 2.7.3-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-15468 | MEDIUM5.02 | libssl3 3.5.4-r0 fixed in 3.5.5-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libssl3 3.5.4-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libssl3 3.5.4-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libssl3 3.5.4-r0 fixed in 3.5.5-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42769 | MEDIUM5.02 | libssl3 3.5.4-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42770 | MEDIUM5.02 | libssl3 3.5.4-r0 fixed in 3.5.7-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libssl3 3.5.4-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libcrypto3 3.5.4-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libssl3 3.5.4-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-15469 | MEDIUM4.67 | libcrypto3 3.5.4-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libcrypto3 3.5.4-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libcrypto3 3.5.4-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-32776 | MEDIUM4.67 | libexpat 2.7.3-r0 fixed in 2.7.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32777 | MEDIUM4.67 | libexpat 2.7.3-r0 fixed in 2.7.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32778 | MEDIUM4.67 | libexpat 2.7.3-r0 fixed in 2.7.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-15469 | MEDIUM4.67 | libssl3 3.5.4-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libssl3 3.5.4-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libssl3 3.5.4-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-6042 | MEDIUM4.67 | musl 1.2.5-r10 fixed in 1.2.5-r11 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-6042 | MEDIUM4.67 | musl-utils 1.2.5-r10 fixed in 1.2.5-r11 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-39833 | MEDIUM4.67 | golang.org/x/crypto v0.42.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-32288 | MEDIUM4.67 | stdlib v1.25.3 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-45571 | MEDIUM4.59 | github.com/go-git/go-git/v5 v5.16.3 fixed in 5.19.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42506 | MEDIUM4.59 | golang.org/x/net v0.44.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27142 | MEDIUM4.59 | stdlib v1.25.3 fixed in 1.25.8, 1.26.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39823 | MEDIUM4.59 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39826 | MEDIUM4.59 | stdlib v1.25.3 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-14831 | MEDIUM4.5 | gnutls 3.8.8-r0 fixed in 3.8.12-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42015 | MEDIUM4.5 | gnutls 3.8.8-r0 fixed in 3.8.13-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | libcrypto3 3.5.4-r0 fixed in 3.5.7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | libcrypto3 3.5.4-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | libssl3 3.5.4-r0 fixed in 3.5.7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | libssl3 3.5.4-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-34743 | MEDIUM4.5 | xz-libs 5.8.1-r0 fixed in 5.8.3-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-68938 | MEDIUM4.5 | code.gitea.io/gitea v1.25.1 fixed in 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69413 | MEDIUM4.5 | code.gitea.io/gitea v1.25.1 fixed in 1.25.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-47914 | MEDIUM4.5 | golang.org/x/crypto v0.42.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-58181 | MEDIUM4.5 | golang.org/x/crypto v0.42.0 fixed in 0.45.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-46598 | MEDIUM4.5 | golang.org/x/crypto v0.42.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-47911 | MEDIUM4.5 | golang.org/x/net v0.44.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-58190 | MEDIUM4.5 | golang.org/x/net v0.44.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-61730 | MEDIUM4.5 | stdlib v1.25.3 fixed in 1.24.12, 1.25.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42505 | MEDIUM4.5 | stdlib v1.25.3 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42507 | MEDIUM4.5 | stdlib v1.25.3 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34165 | MEDIUM4.25 | github.com/go-git/go-git/v5 v5.16.3 fixed in 5.17.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-15467 | MEDIUM4.06 | libcrypto3 3.5.4-r0 fixed in 3.5.5-r0 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2025-15467 | MEDIUM4.06 | libssl3 3.5.4-r0 fixed in 3.5.5-r0 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2025-68160 | MEDIUM4 | libcrypto3 3.5.4-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | libssl3 3.5.4-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69725 | MEDIUM4 | github.com/go-chi/chi/v5 v5.2.3 fixed in 5.2.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-56131 | LOW3.82 | libexpat 2.7.3-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-25934 | LOW3.65 | github.com/go-git/go-git/v5 v5.16.3 fixed in 5.16.5 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-68973 | LOW3.57 | gnupg 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68973 | LOW3.57 | gnupg-dirmngr 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68973 | LOW3.57 | gnupg-gpgconf 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68973 | LOW3.57 | gnupg-keyboxd 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68973 | LOW3.57 | gnupg-utils 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68973 | LOW3.57 | gnupg-wks-client 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68973 | LOW3.57 | gpg 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68973 | LOW3.57 | gpg-agent 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68973 | LOW3.57 | gpg-wks-server 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68973 | LOW3.57 | gpgsm 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68973 | LOW3.57 | gpgv 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-42010 | LOW3.53 | gnutls 3.8.8-r0 fixed in 3.8.13-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-9820 | LOW3.4 | gnutls 3.8.8-r0 fixed in 3.8.12-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW3.4 | libcrypto3 3.5.4-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW3.4 | libssl3 3.5.4-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-33186 | LOW3.28 | google.golang.org/grpc v1.75.0 fixed in 1.79.3 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2026-3832 | LOW3.15 | gnutls 3.8.8-r0 fixed in 3.8.13-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-5419 | LOW3.15 | gnutls 3.8.8-r0 fixed in 3.8.13-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-45446 | LOW3.15 | libcrypto3 3.5.4-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-41080 | LOW3.15 | libexpat 2.7.3-r0 fixed in 2.8.1-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-45446 | LOW3.15 | libssl3 3.5.4-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-26958 | LOW3.15 | filippo.io/edwards25519 v1.1.0 fixed in 1.1.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-31789 | LOW3 | libcrypto3 3.5.4-r0 fixed in 3.5.6-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-31789 | LOW3 | libssl3 3.5.4-r0 fixed in 3.5.6-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-1229 | LOW3 | github.com/cloudflare/circl v1.6.1 fixed in 1.6.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-0798 | LOW2.98 | code.gitea.io/gitea v1.25.1 fixed in 1.25.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-32988 | LOW2.95 | gnutls 3.8.8-r0 fixed in 3.8.12-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | libcrypto3 3.5.4-r0 fixed in 3.5.7-r0 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | libssl3 3.5.4-r0 fixed in 3.5.7-r0 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-33845 | LOW2.78 | gnutls 3.8.8-r0 fixed in 3.8.13-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | libcrypto3 3.5.4-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | libssl3 3.5.4-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-1584 | LOW2.7 | gnutls 3.8.8-r0 fixed in 3.8.12-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28388 | LOW2.7 | libcrypto3 3.5.4-r0 fixed in 3.5.6-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28388 | LOW2.7 | libssl3 3.5.4-r0 fixed in 3.5.6-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-2100 | LOW2.7 | p11-kit 0.25.5-r2 fixed in 0.26.2-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-61984 | LOW2.7 | openssh-keygen 10.0_p1-r9 fixed in 10.0_p1-r10 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-61985 | LOW2.7 | openssh-keygen 10.0_p1-r9 fixed in 10.0_p1-r10 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68972 | LOW2.4 | gnupg 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68972 | LOW2.4 | gnupg-dirmngr 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68972 | LOW2.4 | gnupg-gpgconf 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68972 | LOW2.4 | gnupg-keyboxd 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68972 | LOW2.4 | gnupg-utils 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68972 | LOW2.4 | gnupg-wks-client 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68972 | LOW2.4 | gpg 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68972 | LOW2.4 | gpg-agent 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68972 | LOW2.4 | gpg-wks-server 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68972 | LOW2.4 | gpgsm 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68972 | LOW2.4 | gpgv 2.4.7-r0 fixed in 2.4.9-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-33762 | LOW2.38 | github.com/go-git/go-git/v5 v5.16.3 fixed in 5.17.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-24515 | LOW2.12 | libexpat 2.7.3-r0 fixed in 2.7.4-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27139 | LOW2.12 | stdlib v1.25.3 fixed in 1.25.8, 1.26.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-5545 | LOW1.99 | curl 8.14.1-r2 fixed in 8.14.1-r3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-5545 | LOW1.99 | libcurl 8.14.1-r2 fixed in 8.14.1-r3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox 1.37.0-r19 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox-binsh 1.37.0-r19 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | ssl_client 1.37.0-r19 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2024-58251 | NONE0 | busybox 1.37.0-r19 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox-binsh 1.37.0-r19 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-56408 | NONE0 | libexpat 2.7.3-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56409 | NONE0 | libexpat 2.7.3-r0 fixed in 2.8.2-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | ssl_client 1.37.0-r19 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-20896 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.3 | 31.8% High Exploitation Risk | Not Applicable |
| CVE-2026-22874 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-56750 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58426 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.2 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-58443 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-20779 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-22555 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-24451 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-24791 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.2 | — | Not Applicable |
| CVE-2026-25038 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-26231 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-27771 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.2 | 43.1% High Exploitation Risk | Not Applicable |
| CVE-2026-27775 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-28699 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-28737 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-28744 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54481 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-55987 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-56654 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-56755 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-57894 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58314 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58419 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-58421 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-58422 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-58423 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.3 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-58424 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.3 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-58436 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58437 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-20706 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-25714 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-27761 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-27783 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42931 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-50105 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-55982 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-56443 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-56657 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-57886 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-57897 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58418 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-58425 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58428 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58429 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58432 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58435 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58441 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58442 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58444 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58507 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58510 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-59763 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-59765 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-59766 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| GHSA-rjvx-x5h2-6px5 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.26.0 | — | Not Applicable |
| CVE-2026-23603 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-55984 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58434 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58445 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| CVE-2026-58511 | NONE0 | code.gitea.io/gitea v1.25.1 fixed in 1.27.0 | — | Not Applicable |
| GHSA-w5pp-99ch-qj29 | NONE0 | github.com/go-git/go-git/v5 v5.16.3 fixed in 5.19.1 | — | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.42.0 No fix yet | — | Not Applicable |
| CVE-2026-46602 | NONE0 | golang.org/x/image v0.30.0 fixed in 0.43.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-46604 | NONE0 | golang.org/x/image v0.30.0 fixed in 0.43.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42500 | NONE0 | golang.org/x/image v0.30.0 fixed in 0.41.0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-46600 | NONE0 | golang.org/x/net v0.44.0 fixed in 0.56.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39824 | NONE0 | golang.org/x/sys v0.37.0 fixed in 0.44.0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56852 | NONE0 | golang.org/x/text v0.30.0 fixed in 0.39.0 | 0.4% Theoretical Threat | Not Applicable |
| GHSA-hrxh-6v49-42gf | NONE0 | google.golang.org/grpc v1.75.0 fixed in 1.82.1 | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.