What is CVE-2026-56443?
CVE-2026-56443 is a residual vulnerability after CVE-2026-25714 / PR #37118 that allows bypassing the public-only scope of a token on owners with limited visibility in repository and package categories. This could expose restricted resources. It is recommended to review token policies and apply the latest security updates.
Azərbaycanca: CVE-2026-56443, məhdud görünmə qabiliyyəti (limited-visibility) olan repo və paket sahibləri üzərində token-in yalnız ümumi (public-only) əhatə dairəsinin bypass edilməsinə səbəb olan boşluqdur. Bu problem CVE-2026-25714 / PR #37118-dən sonra qalan qalıq zəiflik kimi ortaya çıxıb. Mümkün istismarın qarşısını almaq üçün müvafiq platformada token siyasətlərini nəzərdən keçirmək və ən son təhlükəsizlik yeniləmələrini tətbiq etmək tövsiyə olunur.
FAQ2
What is the main reason that distinguishes CVE-2026-56443 from the previous CVE-2026-25714?
CVE-2026-56443 is a residual vulnerability that remained after the initial fix made by CVE-2026-25714 / PR #37118. This flaw causes the public-only scope of a token to not be fully blocked on owners with limited visibility in repository and package categories.
On which assets can CVE-2026-56443 bypass restrictions?
This vulnerability allows bypassing the public-only scope of a token on owners with limited visibility in repository and package categories.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.