In Gitea versions before 1.21.2 a medium severity vulnerability CVE-2025-68945 was detected. This vulnerability allows unauthenticated users to access private projects due to improper access control enforcement. To address this issue, users should upgrade Gitea to version 1.21.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-68945.
Read more Developer ToolsIn Forgejo versions prior to 13.0.2 (and 11 LTS prior to 11.0.7) a critical severity vulnerability CVE-2025-68937 was detected. This vulnerability allows attackers to write to unintended files and potentially gain shell access due to improper handling of out-of-repository symlink destinations in template repositories. To address this issue, users should upgrade Forgejo to version 13.0.2 or later, or 11.0.7 or later for the LTS branch. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-68937.
Read more Developer ToolsIn Gitea versions prior to 1.20.1 a medium severity vulnerability CVE-2025-68946 was detected. This vulnerability allows attackers to perform cross-site scripting (XSS) by injecting forbidden URL schemes such as javascript: into links, which can then be executed in a victim’s browser. To address this issue, users should upgrade Gitea to version 1.20.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-68946.
Read more Developer ToolsIn ZITADEL versions 2.44.0 through 3.4.4 and 4.0.0-rc.1 through 4.7.1 a medium severity vulnerability CVE-2025-67717 was detected. This vulnerability allows authenticated users to view the total number of instance users via the totalResult field, regardless of their permissions, potentially disclosing sensitive information. To address this issue users should upgrade to ZITADEL versions 3.4.5, 4.7.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-67717.
Read more Developer ToolsIn ZITADEL versions 2.44.0 through 3.4.4 and 4.0.0-rc.1 through 4.7.1 a medium severity vulnerability CVE-2025-67717 was detected. This vulnerability allows authenticated users to view the total number of instance users via the totalResult field regardless of their assigned permissions, leading to information disclosure that may be sensitive in certain contexts. To address this issue, users should upgrade ZITADEL to versions 3.4.5 or 4.7.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-67717.
Read more Developer ToolsIn Jenkins versions 2.540 and earlier, including LTS 2.528.2 and earlier a high severity vulnerability CVE-2025-67635 was detected. This vulnerability allows unauthenticated attackers to cause a denial of service due to HTTP-based CLI connections not being properly closed when the connection stream becomes corrupted. To address this issue, users should upgrade to Jenkins version 2.541 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-67635.
Read more Developer ToolsIn Gogs versions 0.13.3 and prior a high severity vulnerability CVE-2025-8110 was detected. This vulnerability allows local attackers to execute arbitrary code by exploiting improper symbolic link handling in the `PutContents` file update API. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-8110.
Read more Developer ToolsIn Jenkins versions 2.540 and earlier, including LTS 2.528.2 and earlier a low severity vulnerability CVE-2025-67639 was detected. This vulnerability allows attackers to perform cross-site request forgery (CSRF) attacks that can trick users into logging in to the attacker’s account. To address this issue, users should upgrade Jenkins to versions 2.541 or 2.528.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-67639.
Read more Developer ToolsIn Jenkins versions 2.540 and earlier, including LTS 2.528.2 and earlier a medium severity vulnerability CVE-2025-67638 was detected. This vulnerability allows attackers to observe and capture build authorization tokens because they are not properly masked in the job configuration form. To address this issue, users should upgrade Jenkins to versions 2.541 or 2.528.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-67638.
Read more Developer Tools