Vulnerabilidades em Gitea

112 resultados
Análise Vexday

Gitea apresenta perfil de risco moderado com 63 vulnerabilidades catalogadas, sendo 16 críticas (CVSS≥9) e 41 publicadas nos últimos 90 dias, indicando exposição a descobertas recentes. Apesar da ausência de exploração ativa registrada (KEV=0), a fraqueza dominante CWE-284 (controle de acesso inadequado) representa vetor de risco estrutural que demanda revisão de permissões e segmentação. A velocidade de publicação de vulnerabilidades sugere monitoramento contínuo de patches.

CVE-2026-60004CRITICALGitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.EPSS 86.8%KEVCVE-2024-6886CRITICALInproper Sanitation of field leading to stored XSSEPSS 33.0%CVE-2026-20896CRITICALGitea Docker image trusts spoofable reverse-proxy headers by defaultEPSS 2.8%CVE-2026-27771HIGHGitea Composer package source links use insufficient permission checksEPSS 1.4%CVE-2019-1010314Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable reEPSS 0.8%CVE-2019-1010261Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execute arbitrary JS in bEPSS 0.8%CVE-2026-26292CRITICALGitea LFS mirror synchronization bypasses migration HTTP transport restrictionsEPSS 0.7%CVE-2026-27780CRITICALGitea pre-receive hook can miss branch-protection checks after scanner errorsEPSS 0.6%CVE-2026-26307HIGHGitea git grep search lacks a timeoutEPSS 0.6%CVE-2026-58422CRITICALImproper authorization on OAuth sign-in callback silently re-enables administrator-disabled accountsEPSS 0.6%CVE-2026-58421HIGHUnauthenticated ReDoS via CODEOWNERS pattern matching allows denial of serviceEPSS 0.6%CVE-2026-27779HIGHGitea forwarded-proto handling allows public URL spoofingEPSS 0.6%CVE-2026-58443CRITICALPublic-only repository tokens can update private PR head branchesEPSS 0.6%CVE-2026-20706CRITICALGitea repository archive downloads bypass token scope checksEPSS 0.6%CVE-2026-25718CRITICALGitea template repository generation mishandles symlinked pathsEPSS 0.6%CVE-2026-28699HIGHGitea Basic Auth bypasses OAuth2 access token scopesEPSS 0.6%CVE-2026-58423HIGHLFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositoriesEPSS 0.5%CVE-2026-27775HIGHGitea pre-receive hook permission cache allows full repository write accessEPSS 0.5%CVE-2026-22547CRITICALGitea repository creation accepts invalid field valuesEPSS 0.5%CVE-2026-58419HIGHNotification API leaks private issue metadata after access revocationEPSS 0.5%