CVE-2026-103504
- EPSS 0.26%
- Veröffentlicht 06.10.2026 19:24:26
- Zuletzt bearbeitet 07.10.2026 21:17:07
Changing an organization team's permission through the API with only the `permission` field did not rebuild the team's per-unit access, and the requested level was not applied as a cap. After an organization owner demoted a team, for example from adm...
CVE-2026-95106
- EPSS 0.29%
- Veröffentlicht 06.10.2026 19:23:57
- Zuletzt bearbeitet 07.10.2026 21:17:22
Gitea accepted pushed Git trees containing two entries with the same name, which Git's own consistency checks reject. Gitea's web views resolved such a path to the first entry, while `git checkout`, Gitea Actions, and release archives use the last. A...
CVE-2026-89430
- EPSS 0.19%
- Veröffentlicht 06.10.2026 19:23:52
- Zuletzt bearbeitet 07.10.2026 21:17:21
Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created. Each synchronization passed the stored address directly to `git push`, so a name that later resolved to a blocked or int...
CVE-2026-103670
- EPSS 0.22%
- Veröffentlicht 06.10.2026 19:23:40
- Zuletzt bearbeitet 07.10.2026 16:17:33
When a Gitea Actions run was inserted, older runs in the same workflow-level concurrency group were cancelled without checking whether the new run still needed approval. Because fork pull request runs are inserted under the base repository, a user wh...
CVE-2026-103667
- EPSS 0.17%
- Veröffentlicht 06.10.2026 19:23:34
- Zuletzt bearbeitet 07.10.2026 21:17:07
Gitea's container registry served blob downloads with a `Content-Type` taken from the media type declared in pushed image manifests, without a `Content-Disposition` or restrictive content security policy. A user who can push container images can publ...
CVE-2026-101029
- EPSS 0.17%
- Veröffentlicht 06.10.2026 19:23:26
- Zuletzt bearbeitet 07.10.2026 21:17:06
Gitea's repository migration and pull mirror egress checks could be bypassed with a hostname that returns multiple DNS answers, because the address that was validated was not necessarily the address Git later connected to. A low-privileged user who c...
CVE-2026-101027
- EPSS 0.17%
- Veröffentlicht 06.10.2026 19:23:20
- Zuletzt bearbeitet 07.10.2026 16:17:31
When `[migrations] ALLOWED_DOMAINS` was configured, a hostname matching the allow list was accepted without checking its resolved address against the local-network restrictions. A user who can start repository migrations and control the DNS of an all...
CVE-2026-104626
- EPSS 0.33%
- Veröffentlicht 06.10.2026 19:23:03
- Zuletzt bearbeitet 07.10.2026 21:17:08
A user who can open a fork pull request can place workflow content with a shared run-level concurrency group into a Gitea Actions run that is awaiting approval. When a later run in that group cancels the blocked job, the run becomes terminal while st...
CVE-2026-103059
- EPSS 0.28%
- Veröffentlicht 06.10.2026 19:22:57
- Zuletzt bearbeitet 07.10.2026 15:16:56
When Gitea's built-in SSH server is enabled (`START_SSH_SERVER = true`), the presented public key was looked up with an SQL `LIKE` comparison of its encoded content, which is case-insensitive on some databases, including the default SQLite. An attack...
CVE-2026-104632
- EPSS 0.28%
- Veröffentlicht 06.10.2026 19:22:04
- Zuletzt bearbeitet 07.10.2026 21:17:08
Gitea Actions blocks the jobs of workflow runs from first-time fork pull request contributors until a maintainer approves the run. The rerun path only required a run to be finished and built the new attempt's jobs without considering the pending appr...