Gitea

Gitea

123 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 13.08.2026 16:44:38
  • Zuletzt bearbeitet 14.08.2026 18:17:24

Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

  • EPSS 0.38%
  • Veröffentlicht 13.08.2026 16:44:38
  • Zuletzt bearbeitet 13.08.2026 20:17:21

Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

  • EPSS 0.31%
  • Veröffentlicht 05.08.2026 20:28:57
  • Zuletzt bearbeitet 06.08.2026 16:16:42

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get with...

  • EPSS 0.19%
  • Veröffentlicht 03.07.2026 20:54:53
  • Zuletzt bearbeitet 06.07.2026 18:17:26

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

  • EPSS 0.34%
  • Veröffentlicht 03.07.2026 20:54:52
  • Zuletzt bearbeitet 06.07.2026 18:18:46

Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

  • EPSS 0.31%
  • Veröffentlicht 03.07.2026 20:54:52
  • Zuletzt bearbeitet 06.07.2026 18:18:46

LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

  • EPSS 0.2%
  • Veröffentlicht 03.07.2026 20:54:52
  • Zuletzt bearbeitet 06.07.2026 18:18:46

Permanent Fork PR Workflow Approval Gate Bypass

  • EPSS 0.24%
  • Veröffentlicht 03.07.2026 20:54:51
  • Zuletzt bearbeitet 06.07.2026 18:18:46

SSRF via HTTP Redirect in Repository Migration

  • EPSS 0.33%
  • Veröffentlicht 03.07.2026 20:54:51
  • Zuletzt bearbeitet 06.07.2026 18:18:46

Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

  • EPSS 0.37%
  • Veröffentlicht 03.07.2026 20:19:39
  • Zuletzt bearbeitet 07.07.2026 18:16:38

Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.