9.1
CVE-2026-20706
- EPSS 0.49%
- Veröffentlicht 03.07.2026 20:19:28
- Zuletzt bearbeitet 06.07.2026 19:17:00
- CVE-Watchlists
- Unerledigt
Gitea repository archive downloads bypass token scope checks
Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGitea
≫
Produkt
Gitea Open Source Git Server
Default Statusunaffected
Version <=
1.26.1
Version
0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.49% | 0.394 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://github.com/go-gitea/gitea/security/advisories/GHSA-cr4g-f395-h25h
https://github.com/go-gitea/gitea/pull/37735
https://github.com/go-gitea/gitea/releases/tag/v1.26.2
https://blog.gitea.com/release-of-1.26.2/