CVE-2026-97626
- EPSS 0.2%
- Veröffentlicht 06.10.2026 21:36:48
- Zuletzt bearbeitet 07.10.2026 21:17:22
Requesting a user or organization profile page (`GET /{username}`) with an `Accept: application/rss+xml` or `Accept: application/atom+xml` header returned the owner's activity feed without the visibility check that the profile page and the `.rss` and...
CVE-2026-96594
- EPSS 0.21%
- Veröffentlicht 06.10.2026 21:36:38
- Zuletzt bearbeitet 07.10.2026 16:19:13
The Gitea API endpoint `GET /api/v1/repos/{owner}/{repo}/media/{filepath}` wrote files of up to 1 KiB that are stored directly in Git, not in LFS, to the response without the content type and disposition headers Gitea uses for user content. An HTML f...
CVE-2026-89182
- EPSS 0.18%
- Veröffentlicht 06.10.2026 21:36:01
- Zuletzt bearbeitet 07.10.2026 13:45:36
With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories could make ...
CVE-2026-105268
- EPSS 0.2%
- Veröffentlicht 06.10.2026 21:35:40
- Zuletzt bearbeitet 07.10.2026 17:16:46
The Gitea API routes for issue attachments (`/api/v1/repos/{owner}/{repo}/issues/{index}/assets/{attachment_id}`) also accepted attachments that belong to comments on the issue. Because the author of an issue may edit and delete the issue's attachmen...
CVE-2026-105267
- EPSS 0.38%
- Veröffentlicht 06.10.2026 21:35:35
- Zuletzt bearbeitet 07.10.2026 21:17:11
The Gitea web route for deleting tags (`POST /{owner}/{repo}/tags/delete`) requires only write access to the Code unit, but shares its handler with release deletion and did not check that the target was a plain tag. A collaborator with Code write acc...
CVE-2026-104633
- EPSS 0.39%
- Veröffentlicht 06.10.2026 21:35:26
- Zuletzt bearbeitet 07.10.2026 16:17:33
When migrating a repository from another Gitea instance, Gitea used the page size reported in the source server's API settings to end its paginated downloads. A source that reported `max_response_items` as `0` made these loops run indefinitely and gr...
CVE-2026-101023
- EPSS 0.35%
- Veröffentlicht 06.10.2026 21:34:53
- Zuletzt bearbeitet 07.10.2026 21:17:06
Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the `refresh_token` grant type, but not that the token was a refresh token. An unexpired access token for the same OAuth2 application and grant could be exchange...
CVE-2026-97208
- EPSS 0.27%
- Veröffentlicht 06.10.2026 21:17:46
- Zuletzt bearbeitet 07.10.2026 21:17:22
The Gitea API endpoint for creating push mirrors (`POST /api/v1/repos/{owner}/{repo}/push_mirrors`) checked only whether mirroring was enabled and not the `[mirror] DISABLE_NEW_PUSH` setting that the web interface enforces. A repository administrator...
CVE-2026-86684
- EPSS 0.11%
- Veröffentlicht 06.10.2026 21:17:09
- Zuletzt bearbeitet 07.10.2026 21:17:20
The Gitea push mirror API checked whether the repository owner, instead of the requesting user, may use local file system paths. On instances with `[security] IMPORT_LOCAL_PATHS = true`, a repository administrator who is not allowed to import local p...
CVE-2026-73278
- EPSS 0.47%
- Veröffentlicht 06.10.2026 19:33:54
- Zuletzt bearbeitet 07.10.2026 21:17:16
Gitea's OAuth2 and OpenID Connect sign-in paths do not require a WebAuthn challenge when WebAuthn is the account's only configured second factor. A party able to authenticate through the affected external identity flow can obtain a full session witho...