Vulnerabilidades em Gitea
112 resultadosAnálise Vexday
Gitea apresenta perfil de risco moderado com 63 vulnerabilidades catalogadas, sendo 16 críticas (CVSS≥9) e 41 publicadas nos últimos 90 dias, indicando exposição a descobertas recentes. Apesar da ausência de exploração ativa registrada (KEV=0), a fraqueza dominante CWE-284 (controle de acesso inadequado) representa vetor de risco estrutural que demanda revisão de permissões e segmentação. A velocidade de publicação de vulnerabilidades sugere monitoramento contínuo de patches.
CVE-2026-58418MEDIUMSSRF via HTTP Redirect in Repository MigrationEPSS 0.4%CVE-2026-58420MEDIUMLocal File Inclusion via file:// URI in Migration RestoreEPSS 0.4%CVE-2026-20800MEDIUMNotification API Leaks Private Repository Issue Titles After Collaborator Permission RevocationEPSS 0.4%CVE-2025-69413MEDIUMIn Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.EPSS 0.4%CVE-2026-25782MEDIUMGitea tracked-time deletion can target entries from another issueEPSS 0.4%CVE-2025-68938MEDIUMGitea before 1.25.2 mishandles authorization for deletion of releases.EPSS 0.4%CVE-2026-42931MEDIUMDenial of Service via Unbounded io.ReadAll in NPM Package Tag EndpointEPSS 0.4%CVE-2026-58424HIGHPermanent Fork PR Workflow Approval Gate BypassEPSS 0.4%CVE-2026-55982CRITICALOIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token ScopesEPSS 0.4%CVE-2026-20883MEDIUMGitea Stopwatch API Missing Authorization Check Leads to Post-Revocation Information DisclosureEPSS 0.4%CVE-2026-27761MEDIUMGitea repository feeds bypass API token scope enforcementEPSS 0.4%CVE-2026-56443CRITICALToken public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118EPSS 0.4%CVE-2025-68943MEDIUMGitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.EPSS 0.4%CVE-2025-68945MEDIUMIn Gitea before 1.21.2, an anonymous user can visit a private user's project.EPSS 0.4%CVE-2026-26231HIGHGitea maintainer-edit permissions allow unauthorized commits to readable repositoriesEPSS 0.4%CVE-2026-58429MEDIUMPublic-Only Personal access tokens scope bypass in Organization and Permission EndpointsEPSS 0.3%CVE-2026-25779MEDIUMGitea redirect handling permits open redirects through backslash pathsEPSS 0.3%CVE-2026-27783MEDIUMGitea issue-template APIs bypass repository unit authorizationEPSS 0.3%CVE-2026-58427HIGHPrivate org member list leaked via /members API endpoint — incomplete fix for PR #38145EPSS 0.3%CVE-2026-56750CRITICALGitea Remember-Me Token Theft Not Invalidating Attacker SessionEPSS 0.3%