Vulnerability Reportgitea/gitea:1.26.4-rootless

gitea/gitea:1.26-rootlessgitea/gitea:1.26.4-rootless
digestsha256:cd1d2614b403fc9b085fa52ceb4424dde9c4dcf5da8e3263abb27955562070c4

Executive Summary

Last scanned:

Threat Score
0/100NEEDS ATTENTION
Reputation
RELIABLE

AI verdict failed due to an error.

Vulnerabilities

Vulnerability Log

110 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-5773LOW3.82
curl
8.19.0-r0
fixed in 8.20.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW3.82
curl
8.19.0-r0
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW3.31
curl
8.19.0-r0
fixed in 8.20.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW3.31
curl
8.19.0-r0
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-4873LOW2.7
curl
8.19.0-r0
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
curl
8.19.0-r0
fixed in 8.20.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-7009LOW2.7
curl
8.19.0-r0
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
curl
8.19.0-r0
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-45570NONE0
github.com/go-git/go-git/v5
v5.19.0
fixed in 5.19.1
0.4%
Theoretical Threat
Not Applicable
CVE-2026-45445NONE0
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-45445NONE0
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-45447NONE0
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Not Applicable
CVE-2026-45447NONE0
libssl3
3.5.6-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Not Applicable
CVE-2026-33630NONE0
c-ares
1.34.6-r0
fixed in 1.34.8-r0
Not Applicable
CVE-2026-34183NONE0
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-5773NONE0
libcurl
8.19.0-r0
fixed in 8.20.0-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-6276NONE0
libcurl
8.19.0-r0
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-34183NONE0
libssl3
3.5.6-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-2100NONE0
p11-kit
0.25.5-r2
fixed in 0.26.2-r0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-32952NONE0
github.com/Azure/go-ntlmssp
v0.1.0
fixed in 0.1.1
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-34182NONE0
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-34182NONE0
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-56132NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56403NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56404NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56405NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56406NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56407NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56410NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56411NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-5545NONE0
libcurl
8.19.0-r0
fixed in 8.20.0-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-6429NONE0
libcurl
8.19.0-r0
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-33813NONE0
golang.org/x/image
v0.40.0
fixed in 0.42.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-46599NONE0
golang.org/x/image
v0.40.0
fixed in 0.41.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-46601NONE0
golang.org/x/image
v0.40.0
fixed in 0.43.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-34181NONE0
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42768NONE0
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-34181NONE0
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42768NONE0
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42764NONE0
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-42769NONE0
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42770NONE0
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-9076NONE0
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-50219NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-56412NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-42764NONE0
libssl3
3.5.6-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-42769NONE0
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42770NONE0
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-9076NONE0
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-7383NONE0
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-7383NONE0
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-45571NONE0
github.com/go-git/go-git/v5
v5.19.0
fixed in 5.19.1
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42766NONE0
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Not Applicable
CVE-2026-42767NONE0
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-4873NONE0
libcurl
8.19.0-r0
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-6253NONE0
libcurl
8.19.0-r0
fixed in 8.20.0-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-7009NONE0
libcurl
8.19.0-r0
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-7168NONE0
libcurl
8.19.0-r0
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-42766NONE0
libssl3
3.5.6-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Not Applicable
CVE-2026-42767NONE0
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-34180NONE0
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-34180NONE0
libssl3
3.5.6-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-45446NONE0
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-45446NONE0
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-56131NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56408NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56409NONE0
libexpat
2.8.1-r0
fixed in 2.8.2-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56750NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58443NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-54481NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-55987NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-56654NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-56755NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-57894NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58314NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58436NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58437NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-42931NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-50105NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-55982NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-56443NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-56657NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-57886NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-57897NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58425NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58428NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58429NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58432NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58435NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58441NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58442NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58444NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58507NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58510NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-59763NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-59765NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-59766NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-23603NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-55984NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58434NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58445NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
CVE-2026-58511NONE0
code.gitea.io/gitea
v1.26.4+dirty
fixed in 1.27.0
Not Applicable
GHSA-w5pp-99ch-qj29NONE0
github.com/go-git/go-git/v5
v5.19.0
fixed in 5.19.1
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.52.0
No fix yet
Not Applicable
CVE-2026-46602NONE0
golang.org/x/image
v0.40.0
fixed in 0.43.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-46604NONE0
golang.org/x/image
v0.40.0
fixed in 0.43.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42500NONE0
golang.org/x/image
v0.40.0
fixed in 0.41.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.55.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.37.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.79.3
fixed in 1.82.1
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.