CVE-2026-96589
- EPSS 0.22%
- Veröffentlicht 06.10.2026 19:25:38
- Zuletzt bearbeitet 07.10.2026 15:17:59
When a private repository is transferred to a user who lacks access, Gitea grants that recipient temporary read access as a collaborator so they can review the repository. Rejecting or cancelling the transfer did not revoke this collaboration, so the...
CVE-2026-96580
- EPSS 0.35%
- Veröffentlicht 06.10.2026 19:25:33
- Zuletzt bearbeitet 07.10.2026 21:17:22
Gitea expanded a workflow's static `strategy.matrix` into its full Cartesian product without a size limit when creating a run, before the fork pull request approval gate applied. A user who can open a pull request from a fork could submit a small wor...
CVE-2026-96404
- EPSS 0.41%
- Veröffentlicht 06.10.2026 19:25:28
- Zuletzt bearbeitet 07.10.2026 15:17:58
When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the install form with an administrator username matching an existing account issued an authenti...
CVE-2026-96400
- EPSS 0.2%
- Veröffentlicht 06.10.2026 19:25:23
- Zuletzt bearbeitet 07.10.2026 13:45:36
With `[migrations] ALLOWED_DOMAINS` set to a matching entry such as `*` or a hostname wildcard, Gitea's migration URL validation could permit reserved and link-local addresses, such as `169.254.169.254`, even when `ALLOW_LOCALNETWORKS = false`. The l...
CVE-2026-96399
- EPSS 0.35%
- Veröffentlicht 06.10.2026 19:25:18
- Zuletzt bearbeitet 07.10.2026 21:17:22
A repository's external issue tracker regular expression containing alternating capture groups could produce invalid slice indexes when Gitea rendered issue references, causing a runtime panic that terminated the Gitea process. A user who can edit a ...
CVE-2026-95112
- EPSS 0.16%
- Veröffentlicht 06.10.2026 19:25:12
- Zuletzt bearbeitet 08.10.2026 13:17:22
When processing issue and comment bodies, Gitea scanned the entire preceding text for action keywords such as "closes" or "fixes" once per Markdown link, giving processing time quadratic in the input size. An authenticated user able to submit issue o...
CVE-2026-94205
- EPSS 0.34%
- Veröffentlicht 06.10.2026 19:25:04
- Zuletzt bearbeitet 07.10.2026 21:17:21
Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the event rather than the pull request author. For `pull_request` activity triggered by a maintainer during ordinary triage, such as adding a label,...
CVE-2026-79960
- EPSS 0.21%
- Veröffentlicht 06.10.2026 19:24:55
- Zuletzt bearbeitet 07.10.2026 15:17:54
When a push was authenticated with a deploy key, Gitea recorded the repository owner as the pusher, so permission checks in the push hook pipeline evaluated the owner instead of the deploy key. A holder of a writable deploy key could create protected...
CVE-2026-70357
- EPSS 0.26%
- Veröffentlicht 06.10.2026 19:24:50
- Zuletzt bearbeitet 07.10.2026 21:17:16
Gitea validates a repository migration hostname against its network allow and block lists before invoking Git, but the Git subprocess independently resolves the hostname when connecting. An attacker who can start a migration and control the destinati...
CVE-2026-104636
- EPSS 0.26%
- Veröffentlicht 06.10.2026 19:24:45
- Zuletzt bearbeitet 07.10.2026 21:17:09
Gitea validated the initial remote URL for push mirrors, wiki remote checks, and fetches of migrated pull request heads, but the subsequent raw Git operations followed HTTP redirects without revalidating the destination. A repository administrator us...