Threats Tagged 'ghsa-q9pg-jj6x-j9p6'
View all threats tagged with 'ghsa-q9pg-jj6x-j9p6'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-q9pg-jj6x-j9p6'
Click on any threat for detailed analysis and mitigation recommendations
Gitea: draft release attachment disclosure via missing web authorization (CVE-2026-58432)CVE-2026-58432 0 Gitea versions prior to 1.27.0 have a vulnerability where draft release attachments can be accessed without proper authorization via web endpoints. Although draft releases are hidden from listings and API lookups, the web-level UUID-based attachment URLs do not enforce draft status checks, allowing anyone with the UUID to download the attachment contents. This occurs because the web handler checks only read permissions on the repository but does not verify if the release is a draft, unlike the API which requires write access. The vulnerability exposes potentially sensitive draft release attachments to unauthorized users if the UUID is leaked or shared. Join the discussion | GCVE Database | 07/21/2026, 20:19:25 UTC Added: 07/22/2026, 00:11:39 UTC |
Showing 1 to 1 of 1 result