Vulnerability Reportgitea/gitea:1.26.2-rootless

gitea/gitea:1.26.2-rootless
digestsha256:c5c21a7705a16f2b2369384a3b7d67c5ed761a818bbb0a55187b5cf98cdc2e68

Executive Summary

Last scanned:

Threat Score
50/100CAUTION
Reputation
RELIABLE

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. The main practical risk is stored XSS via CVE-2026-25681 and CVE-2026-27136, which affect Gitea's rendering of user-generated Markdown/HTML and could lead to session hijacking or account takeover. Upgrading golang.org/x/net to a patched release eliminates these specific vulnerabilities. The library's high reputation and pinned digest are positive, but the breadth of exposed issues warrants caution.

Vulnerabilities

Vulnerability Log

146 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-25681MEDIUM6.88
golang.org/x/net
v0.53.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-27136MEDIUM6.88
golang.org/x/net
v0.53.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-6732MEDIUM6.38
libxml2
2.13.9-r0
fixed in 2.13.9-r1
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-46597MEDIUM6.38
golang.org/x/crypto
v0.50.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42508MEDIUM6.29
golang.org/x/crypto
v0.50.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-46595MEDIUM6.03
golang.org/x/crypto
v0.50.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-39828MEDIUM5.98
golang.org/x/crypto
v0.50.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42764MEDIUM5.9
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-42764MEDIUM5.9
libssl3
3.5.6-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-56132MEDIUM5.87
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56403MEDIUM5.87
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56404MEDIUM5.87
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56405MEDIUM5.87
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56406MEDIUM5.87
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56407MEDIUM5.87
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56410MEDIUM5.87
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56411MEDIUM5.87
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-39821MEDIUM5.58
golang.org/x/net
v0.53.0
fixed in 0.55.0
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39827MEDIUM5.52
golang.org/x/crypto
v0.50.0
fixed in 0.52.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39834MEDIUM5.52
golang.org/x/crypto
v0.50.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33813MEDIUM5.52
golang.org/x/image
v0.38.0
fixed in 0.42.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-46599MEDIUM5.52
golang.org/x/image
v0.38.0
fixed in 0.41.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-46601MEDIUM5.52
golang.org/x/image
v0.38.0
fixed in 0.43.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-25680MEDIUM5.52
golang.org/x/net
v0.53.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39831MEDIUM5.5
golang.org/x/crypto
v0.50.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-34181MEDIUM5.35
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33812MEDIUM5.18
golang.org/x/image
v0.38.0
fixed in 0.39.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.53.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-39829MEDIUM5.1
golang.org/x/crypto
v0.50.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39830MEDIUM5.1
golang.org/x/crypto
v0.50.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42769MEDIUM5.02
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-50219MEDIUM5.02
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-56412MEDIUM5.02
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM5
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-34180MEDIUM5
libssl3
3.5.6-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-7383MEDIUM4.67
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39833MEDIUM4.67
golang.org/x/crypto
v0.50.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45571MEDIUM4.59
github.com/go-git/go-git/v5
v5.19.0
fixed in 5.19.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.53.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libssl3
3.5.6-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-46598MEDIUM4.5
golang.org/x/crypto
v0.50.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39835LOW3.83
golang.org/x/crypto
v0.50.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-56131LOW3.82
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41080LOW3.15
libexpat
2.7.5-r0
fixed in 2.8.1-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45570LOW2.94
github.com/go-git/go-git/v5
v5.19.0
fixed in 5.19.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
libssl3
3.5.6-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-45445LOW2.78
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-33630LOW2.7
c-ares
1.34.6-r0
fixed in 1.34.8-r0
Post-Exploit
CVE-2026-34183LOW2.7
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-34183LOW2.7
libssl3
3.5.6-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-2100LOW2.7
p11-kit
0.25.5-r2
fixed in 0.26.2-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-32952LOW2.7
github.com/Azure/go-ntlmssp
v0.1.0
fixed in 0.1.1
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-4873LOW2.7
curl
8.19.0-r0
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
curl
8.19.0-r0
fixed in 8.20.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-7009LOW2.7
curl
8.19.0-r0
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
curl
8.19.0-r0
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-4873LOW2.7
libcurl
8.19.0-r0
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
libcurl
8.19.0-r0
fixed in 8.20.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-7009LOW2.7
libcurl
8.19.0-r0
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
libcurl
8.19.0-r0
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-39832LOW2.66
golang.org/x/crypto
v0.50.0
fixed in 0.52.0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW2.29
curl
8.19.0-r0
fixed in 8.20.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW2.29
curl
8.19.0-r0
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW2.29
libcurl
8.19.0-r0
fixed in 8.20.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW2.29
libcurl
8.19.0-r0
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45186LOW2.29
libexpat
2.7.5-r0
fixed in 2.8.1-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW1.99
curl
8.19.0-r0
fixed in 8.20.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW1.99
curl
8.19.0-r0
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW1.99
libcurl
8.19.0-r0
fixed in 8.20.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW1.99
libcurl
8.19.0-r0
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-56408NONE0
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56409NONE0
libexpat
2.7.5-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-20896NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.26.3
31.8%
High Exploitation Risk
Not Applicable
CVE-2026-22874NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-56750NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58443NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-20779NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-24451NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-25038NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27775NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-54481NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-55987NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-56654NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-56755NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-57894NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58314NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58419NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58421NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58422NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58423NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-58424NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.26.3
0.2%
Theoretical Threat
Not Applicable
CVE-2026-58436NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58437NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-27761NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42931NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-50105NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-55982NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-56443NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-56657NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-57886NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-57897NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58418NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.26.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-58425NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58428NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58429NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58432NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58435NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58441NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58442NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58444NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58507NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58510NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-59763NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-59765NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-59766NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-23603NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-55984NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58434NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58445NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58511NONE0
code.gitea.io/gitea
v1.26.2+dirty
fixed in 1.27.0
Not Applicable
GHSA-w5pp-99ch-qj29NONE0
github.com/go-git/go-git/v5
v5.19.0
fixed in 5.19.1
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.50.0
No fix yet
Not Applicable
CVE-2026-46602NONE0
golang.org/x/image
v0.38.0
fixed in 0.43.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-46604NONE0
golang.org/x/image
v0.38.0
fixed in 0.43.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42500NONE0
golang.org/x/image
v0.38.0
fixed in 0.41.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.53.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.36.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.79.3
fixed in 1.82.1
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.