Gitea

Gitea

123 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 13.08.2026 16:44:49
  • Zuletzt bearbeitet 14.08.2026 18:18:23

Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

  • EPSS 0.17%
  • Veröffentlicht 13.08.2026 16:44:49
  • Zuletzt bearbeitet 14.08.2026 18:18:23

Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

  • EPSS 0.15%
  • Veröffentlicht 13.08.2026 16:44:49
  • Zuletzt bearbeitet 14.08.2026 18:18:23

Public-only API token restriction is not enforced on team API routes

  • EPSS 0.16%
  • Veröffentlicht 13.08.2026 16:44:48
  • Zuletzt bearbeitet 14.08.2026 18:18:23

Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

  • EPSS 0.16%
  • Veröffentlicht 13.08.2026 16:44:47
  • Zuletzt bearbeitet 14.08.2026 18:18:22

REST API exposes organization membership of private organizations to public

  • EPSS 0.3%
  • Veröffentlicht 13.08.2026 16:44:47
  • Zuletzt bearbeitet 14.08.2026 18:18:22

Local File Inclusion via file:// URI in Migration Restore

  • EPSS 0.16%
  • Veröffentlicht 13.08.2026 16:44:47
  • Zuletzt bearbeitet 14.08.2026 18:18:23

OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

  • EPSS 0.25%
  • Veröffentlicht 13.08.2026 16:44:46
  • Zuletzt bearbeitet 13.08.2026 19:17:26

Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

  • EPSS 0.16%
  • Veröffentlicht 13.08.2026 16:44:45
  • Zuletzt bearbeitet 14.08.2026 18:18:19

Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

  • EPSS 0.3%
  • Veröffentlicht 13.08.2026 16:44:45
  • Zuletzt bearbeitet 13.08.2026 19:17:26

Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs