CVE-2026-58510CWE-200CWE-281CWE-359information-disclosure
CVE-2026-58510
Medium · published August 13, 2026
What it is
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
The record
Technical detail
- CVSS v3.1
- 4.3 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00209 · 11.0th percentile
- Weaknesses
- CWE-200 · Exposure of Sensitive Information to an Unauthorized Actor; CWE-281 · Improper Preservation of Permissions; CWE-359 · Exposure of Private Personal Information to an Unauthorized Actor
- Published
- 2026-08-13T21:17Z
References (3)
EPSS history
Timeline