CVE-2026-58510CWE-200CWE-281CWE-359information-disclosure

CVE-2026-58510

Medium · published August 13, 2026

CVSS v3.1
4.3
EPSS
0%
Percentile
11.0
In the wild
Unconfirmed
What it is

GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00209 · 11.0th percentile
Weaknesses
CWE-200 · Exposure of Sensitive Information to an Unauthorized Actor; CWE-281 · Improper Preservation of Permissions; CWE-359 · Exposure of Private Personal Information to an Unauthorized Actor
Published
2026-08-13T21:17Z
References (3)
EPSS history
Timeline
  • 13 AUG 16:44Z
    GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
    cvelistv5