Gitea

Gitea

123 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 13.08.2026 16:48:52
  • Zuletzt bearbeitet 14.08.2026 18:17:24

The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET req...

  • EPSS 0.25%
  • Veröffentlicht 13.08.2026 16:48:52
  • Zuletzt bearbeitet 13.08.2026 19:17:19

Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

  • EPSS 0.16%
  • Veröffentlicht 13.08.2026 16:44:59
  • Zuletzt bearbeitet 14.08.2026 19:17:23

SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

  • EPSS 0.19%
  • Veröffentlicht 13.08.2026 16:44:58
  • Zuletzt bearbeitet 13.08.2026 20:17:23

GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

  • EPSS 0.24%
  • Veröffentlicht 13.08.2026 16:44:58
  • Zuletzt bearbeitet 13.08.2026 19:17:29

Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

  • EPSS 0.15%
  • Veröffentlicht 13.08.2026 16:44:57
  • Zuletzt bearbeitet 14.08.2026 19:17:20

Private Repository Existence Disclosure via go-get Meta Endpoint

  • EPSS 0.15%
  • Veröffentlicht 13.08.2026 16:44:57
  • Zuletzt bearbeitet 14.08.2026 19:17:21

Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)

  • EPSS 0.16%
  • Veröffentlicht 13.08.2026 16:44:56
  • Zuletzt bearbeitet 14.08.2026 19:17:20

Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

  • EPSS 0.15%
  • Veröffentlicht 13.08.2026 16:44:56
  • Zuletzt bearbeitet 14.08.2026 19:17:20

Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

  • EPSS 0.24%
  • Veröffentlicht 13.08.2026 16:44:55
  • Zuletzt bearbeitet 14.08.2026 20:16:55

Public-only repository tokens can update private PR head branches