Vulnerabilidades en Gitea
112 resultadosAnálisis Vexday
Gitea apresenta perfil de risco moderado com 63 vulnerabilidades catalogadas, sendo 16 críticas (CVSS≥9) e 41 publicadas nos últimos 90 dias, indicando exposição a descobertas recentes. Apesar da ausência de exploração ativa registrada (KEV=0), a fraqueza dominante CWE-284 (controle de acesso inadequado) representa vetor de risco estrutural que demanda revisão de permissões e segmentação. A velocidade de publicação de vulnerabilidades sugere monitoramento contínuo de patches.
CVE-2026-26247CRITICALGitea OAuth2 PKCE S256 challenges are not enforced during token exchangeEPSS 0.5%CVE-2026-26232CRITICALGitea OAuth2 authorization codes lack expiry and reuse enforcementEPSS 0.5%CVE-2026-25038HIGHGitea private organization labels are visible to unauthorized usersEPSS 0.5%CVE-2026-24451HIGHGitea fork synchronization can expose private parent repository dataEPSS 0.5%CVE-2026-25712HIGHGitea organization permission APIs expose private visibility informationEPSS 0.5%CVE-2026-20779HIGHGitea TOTP single-use enforcement defect allows OTP replayEPSS 0.5%CVE-2026-22874CRITICALGitea webhook and migration allow-list filtering permits SSRFEPSS 0.5%CVE-2026-20897CRITICALGitea Git LFS Lock Deletion Broken Access Control (Cross-Repo IDOR)EPSS 0.5%CVE-2026-20912CRITICALGitea: Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attachment DisclosureEPSS 0.5%CVE-2026-28705MEDIUMGitea repository dumps write release assets using unsafe path namesEPSS 0.5%CVE-2026-24690HIGHGitea pull-request branch updates use insufficient permission checksEPSS 0.5%CVE-2026-27657HIGHGitea email settings allow changing another user's primary email addressEPSS 0.5%CVE-2026-27660HIGHGitea draft releases use insufficient permission checksEPSS 0.5%CVE-2026-28744HIGHGitea Git smart HTTP bypasses repository token scopes for bearer tokensEPSS 0.4%CVE-2026-58053CRITICALGitea act_runner - Container Hardening Bypass via Workflow Container OptionsEPSS 0.4%CVE-2026-20736HIGHGitea Web Attachment Deletion: Cross-Repository Unauthorized Deletion via Missing Repo Ownership CheckEPSS 0.4%CVE-2026-20750CRITICALGitea Organization Projects Cross-Organization Authorization Bypass via Project ID (IDOR)EPSS 0.4%CVE-2026-28737HIGHGitea 3D file viewer allows stored XSS through glTF extensionsRequiredEPSS 0.4%CVE-2026-22555HIGHGitea organization forks can expose organization secrets without create permissionEPSS 0.4%CVE-2026-56654CRITICALPrivilege Escalation via Access Token Scope Escalation in APIEPSS 0.4%