CVE-2026-28737
- EPSS 0.34%
- Veröffentlicht 03.07.2026 20:19:39
- Zuletzt bearbeitet 07.07.2026 18:16:38
Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer.
CVE-2026-28740
- EPSS 0.27%
- Veröffentlicht 03.07.2026 20:19:39
- Zuletzt bearbeitet 07.07.2026 18:16:38
Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.
CVE-2026-28699
- EPSS 0.57%
- Veröffentlicht 03.07.2026 20:19:38
- Zuletzt bearbeitet 06.07.2026 18:17:26
Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.
CVE-2026-27775
- EPSS 0.57%
- Veröffentlicht 03.07.2026 20:19:37
- Zuletzt bearbeitet 06.07.2026 18:17:26
Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-edit grant to be reused for other refs and escalate to full repository write access.
CVE-2026-27779
- EPSS 0.43%
- Veröffentlicht 03.07.2026 20:19:37
- Zuletzt bearbeitet 06.07.2026 18:17:26
Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
CVE-2026-27780
- EPSS 0.47%
- Veröffentlicht 03.07.2026 20:19:37
- Zuletzt bearbeitet 06.07.2026 18:17:26
Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.
CVE-2026-27761
- EPSS 0.37%
- Veröffentlicht 03.07.2026 20:19:36
- Zuletzt bearbeitet 07.07.2026 18:16:37
Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.
CVE-2026-27771
- EPSS 43.07%
- Veröffentlicht 03.07.2026 20:19:36
- Zuletzt bearbeitet 07.07.2026 18:16:37
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
CVE-2026-27657
- EPSS 0.35%
- Veröffentlicht 03.07.2026 20:19:35
- Zuletzt bearbeitet 07.07.2026 18:16:37
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
CVE-2026-26231
- EPSS 0.29%
- Veröffentlicht 03.07.2026 20:19:34
- Zuletzt bearbeitet 07.07.2026 18:16:37
Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.