CVE-2026-23603
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:44:38
- Zuletzt bearbeitet 14.08.2026 18:17:24
Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
CVE-2026-42931
- EPSS 0.38%
- Veröffentlicht 13.08.2026 16:44:38
- Zuletzt bearbeitet 13.08.2026 20:17:21
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
CVE-2026-34966
- EPSS 0.31%
- Veröffentlicht 05.08.2026 20:28:57
- Zuletzt bearbeitet 06.08.2026 16:16:42
Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get with...
CVE-2026-58426
- EPSS 0.19%
- Veröffentlicht 03.07.2026 20:54:53
- Zuletzt bearbeitet 06.07.2026 18:17:26
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
CVE-2026-58422
- EPSS 0.34%
- Veröffentlicht 03.07.2026 20:54:52
- Zuletzt bearbeitet 06.07.2026 18:18:46
Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
CVE-2026-58423
- EPSS 0.31%
- Veröffentlicht 03.07.2026 20:54:52
- Zuletzt bearbeitet 06.07.2026 18:18:46
LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
CVE-2026-58424
- EPSS 0.2%
- Veröffentlicht 03.07.2026 20:54:52
- Zuletzt bearbeitet 06.07.2026 18:18:46
Permanent Fork PR Workflow Approval Gate Bypass
CVE-2026-58418
- EPSS 0.24%
- Veröffentlicht 03.07.2026 20:54:51
- Zuletzt bearbeitet 06.07.2026 18:18:46
SSRF via HTTP Redirect in Repository Migration
CVE-2026-58421
- EPSS 0.33%
- Veröffentlicht 03.07.2026 20:54:51
- Zuletzt bearbeitet 06.07.2026 18:18:46
Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
CVE-2026-28705
- EPSS 0.37%
- Veröffentlicht 03.07.2026 20:19:39
- Zuletzt bearbeitet 07.07.2026 18:16:38
Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.