Skip to content

Clarification re: GHSA-2wm4-vwp6-v7xc / CVE-2026-34966 / CVE-2026-59765 #38879

Description

@malte-nyanbinary

Gitea Version

n/a

What happened?

Apologies for misusing the Bug Report template here, unfortunately no Documentation Issue template or similar exists.

CVE-2026-34966 is a CVE assigned by VulnCheck for go-gitea/gitea. It references GHSA-2wm4-vwp6-v7xc. This in turn only names CVE-2026-59765 as the CVE ID. CVE-2026-59765 does not exist in any published or retracted state.

I assume this is due to VulnCheck publishing CVE-2026-34966 even though Gitea is its own CNA & reserving CVE-2026-59765?

If so & if there are no plans to replace the VulnCheck CVE with the Gitea CVE: Would it be possible to update the GHSA to include the correct CVE & reject the unpublished CVE?

If there are plans to replace the CVE: Would it be possible to include both IDs in the CVE in the interim?

If I am completely misunderstanding the situation & these are different vulnerabilities: Apologies - would it still be possible to get some clarification here, e.g. if this is just an issue in the VulnCheck CVE record?

How are you running Gitea?

No response

Metadata

Metadata

Labels

type/questionIssue needs no code to be fixed, only a description on how to fix it yourself.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions