Gitea

Gitea

154 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 03.07.2026 20:19:34
  • Zuletzt bearbeitet 07.07.2026 18:16:37

Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.

  • EPSS 0.38%
  • Veröffentlicht 03.07.2026 20:19:34
  • Zuletzt bearbeitet 07.07.2026 18:16:37

Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.

  • EPSS 0.38%
  • Veröffentlicht 03.07.2026 20:19:34
  • Zuletzt bearbeitet 07.07.2026 18:16:37

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.

  • EPSS 0.25%
  • Veröffentlicht 03.07.2026 20:19:33
  • Zuletzt bearbeitet 07.07.2026 18:16:36

Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect_to values.

  • EPSS 0.42%
  • Veröffentlicht 03.07.2026 20:19:32
  • Zuletzt bearbeitet 07.07.2026 18:16:36

Gitea 1.26.2 allows unauthorized users to access labels of private organizations.

  • EPSS 0.35%
  • Veröffentlicht 03.07.2026 20:19:32
  • Zuletzt bearbeitet 07.07.2026 18:16:36

Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.

  • EPSS 0.33%
  • Veröffentlicht 03.07.2026 20:19:32
  • Zuletzt bearbeitet 07.07.2026 18:16:36

Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.

  • EPSS 0.31%
  • Veröffentlicht 03.07.2026 20:19:30
  • Zuletzt bearbeitet 06.07.2026 21:16:54

Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.

  • EPSS 0.4%
  • Veröffentlicht 03.07.2026 20:19:29
  • Zuletzt bearbeitet 07.07.2026 18:16:35

Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.

  • EPSS 0.29%
  • Veröffentlicht 03.07.2026 20:19:29
  • Zuletzt bearbeitet 07.07.2026 18:16:35

Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.