CVE-2026-60004
- EPSS 84.55%
- Veröffentlicht 26.08.2026 19:45:00
- Zuletzt bearbeitet 27.08.2026 11:41:19
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
CVE-2026-24059
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:48:52
- Zuletzt bearbeitet 26.08.2026 16:53:48
The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET req...
CVE-2026-24791
- EPSS 0.25%
- Veröffentlicht 13.08.2026 16:48:52
- Zuletzt bearbeitet 26.08.2026 16:53:48
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
CVE-2026-59765
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:59
- Zuletzt bearbeitet 26.08.2026 16:53:48
SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
CVE-2026-58510
- EPSS 0.19%
- Veröffentlicht 13.08.2026 16:44:58
- Zuletzt bearbeitet 26.08.2026 16:53:48
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
CVE-2026-59763
- EPSS 0.24%
- Veröffentlicht 13.08.2026 16:44:58
- Zuletzt bearbeitet 26.08.2026 16:53:48
Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
CVE-2026-58507
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:57
- Zuletzt bearbeitet 26.08.2026 16:53:48
Private Repository Existence Disclosure via go-get Meta Endpoint
CVE-2026-58508
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:57
- Zuletzt bearbeitet 26.08.2026 16:53:48
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
CVE-2026-58444
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:56
- Zuletzt bearbeitet 26.08.2026 16:53:48
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
CVE-2026-58445
- EPSS 0.15%
- Veröffentlicht 13.08.2026 16:44:56
- Zuletzt bearbeitet 26.08.2026 16:53:48
Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API