Vulnerabilities in Gitea

112 results
Vexday analysis

Gitea apresenta perfil de risco moderado com 63 vulnerabilidades catalogadas, sendo 16 críticas (CVSS≥9) e 41 publicadas nos últimos 90 dias, indicando exposição a descobertas recentes. Apesar da ausência de exploração ativa registrada (KEV=0), a fraqueza dominante CWE-284 (controle de acesso inadequado) representa vetor de risco estrutural que demanda revisão de permissões e segmentação. A velocidade de publicação de vulnerabilidades sugere monitoramento contínuo de patches.

CVE-2026-25714MEDIUMGitea user organization API bypasses public-only token filteringEPSS 0.3%CVE-2026-58417HIGHREST API exposes organization membership of private organizations to publicEPSS 0.3%CVE-2026-55984LOWNull Pointer Dereference in AddTime API Causes Authenticated Denial of ServiceEPSS 0.3%CVE-2026-58436HIGHParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requestsEPSS 0.3%CVE-2026-20888MEDIUMGitea Pull Requests Auto-Merge: Read-Only Users Can Cancel Scheduled Auto-Merge via Web Endpoint (Authorization Bypass)EPSS 0.3%CVE-2025-68939HIGHGitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.EPSS 0.3%CVE-2026-58428MEDIUMRelease attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)EPSS 0.3%CVE-2026-28740HIGHGitea LFS object reuse bypasses Code-unit authorizationEPSS 0.3%CVE-2026-34966HIGHGitea prior to 1.27.0 SSRF via Migration URI Fetch BypassEPSS 0.3%CVE-2026-20904MEDIUMGitea: Broken access control in OpenID visibility toggle enables cross-user visibility changesEPSS 0.3%CVE-2026-24059MEDIUMGitea runner registration-token GET endpoint performs a write under a read-only token scopeEPSS 0.3%CVE-2026-59765HIGHSSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud MetadataEPSS 0.3%CVE-2026-58426CRITICALGitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state writeEPSS 0.3%CVE-2026-57897MEDIUMCross-Repo Information Disclosure via Org-Level Actions Run/Job APIsEPSS 0.3%CVE-2026-55987HIGHOAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)EPSS 0.3%CVE-2026-58314HIGHTwo SSRF findings in Gitea 1.26.2EPSS 0.3%CVE-2026-54481HIGHInternal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)EPSS 0.3%CVE-2026-20909MEDIUMGitea tracked-time list endpoint has insufficient permission checksEPSS 0.3%CVE-2026-50105MEDIUMRSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)EPSS 0.3%CVE-2026-58439HIGHBranch Protection Bypass via PR Retargeting Preserves Stale `official` Approval FlagEPSS 0.3%