Gitea

Gitea

123 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 13.08.2026 16:44:44
  • Zuletzt bearbeitet 13.08.2026 19:17:25

Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload

  • EPSS 0.17%
  • Veröffentlicht 13.08.2026 16:44:43
  • Zuletzt bearbeitet 13.08.2026 19:17:24

Gitea SSH Key Parser Denial of Service

  • EPSS 0.16%
  • Veröffentlicht 13.08.2026 16:44:43
  • Zuletzt bearbeitet 14.08.2026 20:16:53

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

  • EPSS 0.16%
  • Veröffentlicht 13.08.2026 16:44:42
  • Zuletzt bearbeitet 14.08.2026 20:16:53

OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)

  • EPSS 0.17%
  • Veröffentlicht 13.08.2026 16:44:42
  • Zuletzt bearbeitet 14.08.2026 20:16:53

Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118

  • EPSS 0.16%
  • Veröffentlicht 13.08.2026 16:44:42
  • Zuletzt bearbeitet 14.08.2026 20:16:53

Privilege Escalation via Access Token Scope Escalation in API

  • EPSS 0.17%
  • Veröffentlicht 13.08.2026 16:44:40
  • Zuletzt bearbeitet 14.08.2026 18:18:13

OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

  • EPSS 0.16%
  • Veröffentlicht 13.08.2026 16:44:40
  • Zuletzt bearbeitet 14.08.2026 18:18:13

Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

  • EPSS 0.17%
  • Veröffentlicht 13.08.2026 16:44:39
  • Zuletzt bearbeitet 14.08.2026 21:17:18

RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

  • EPSS 0.16%
  • Veröffentlicht 13.08.2026 16:44:39
  • Zuletzt bearbeitet 14.08.2026 18:18:04

Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)