| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| SQL injection in the Zalktis accounting application via
trading-partner-controlled text fields in received electronic invoices. When
importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis
concatenates partner-controlled values directly into SQL statement text using
string concatenation, with neither parameterised queries nor escaping. The
application's own escaping helper, Dazadi.sql_txt(),
is not invoked on these code paths, so a party that sends an invoice can break
out of the string literal and alter the query logic.
This issue affects Zalktis: before 2026.1.586 and before 2026.2.592. |
| ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests |
| Gitea LFS Deploy-Key Privilege Escalation |
| Private Repository Metadata Remains Accessible After Access Revocation |
| Public-only API token restriction is not enforced on team API routes |
| Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints |
| Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) |
| Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 |
| OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) |
| Local File Inclusion via file:// URI in Migration Restore |
| REST API exposes organization membership of private organizations to public |
| Two SSRF findings in Gitea 1.26.2 |
| Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration |
| Cross-repository issue/comment attachment re-linking can expose private attachment content |
| Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service |
| OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes |
| Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295) |
| Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-read access to instantiate arbitrary `airflow.*` classes on the API server (CWE-502). An authenticated user who can write an XCom value and then read it back with `deserialize=true` triggers the unsafe instantiation. Users are advised to upgrade to apache-airflow 3.3.1 or later, which rejects reserved XCom serialization keys submitted as JSON string literals. |
| Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user's credentials. This has been fixed in 8.2.3. No known workarounds are available. |
| The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked read:user-scoped token can therefore mint a registration token and register a malicious Actions runner that executes workflow jobs with access to repository secrets and source code. |