Gitea

Gitea

123 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 03.07.2026 20:19:34
  • Zuletzt bearbeitet 07.07.2026 18:16:37

Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.

  • EPSS 0.38%
  • Veröffentlicht 03.07.2026 20:19:34
  • Zuletzt bearbeitet 07.07.2026 18:16:37

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.

  • EPSS 0.25%
  • Veröffentlicht 03.07.2026 20:19:33
  • Zuletzt bearbeitet 07.07.2026 18:16:36

Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect_to values.

  • EPSS 0.42%
  • Veröffentlicht 03.07.2026 20:19:32
  • Zuletzt bearbeitet 07.07.2026 18:16:36

Gitea 1.26.2 allows unauthorized users to access labels of private organizations.

  • EPSS 0.35%
  • Veröffentlicht 03.07.2026 20:19:32
  • Zuletzt bearbeitet 07.07.2026 18:16:36

Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.

  • EPSS 0.33%
  • Veröffentlicht 03.07.2026 20:19:32
  • Zuletzt bearbeitet 07.07.2026 18:16:36

Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.

  • EPSS 0.31%
  • Veröffentlicht 03.07.2026 20:19:30
  • Zuletzt bearbeitet 06.07.2026 21:16:54

Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.

  • EPSS 0.4%
  • Veröffentlicht 03.07.2026 20:19:29
  • Zuletzt bearbeitet 07.07.2026 18:16:35

Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.

  • EPSS 0.29%
  • Veröffentlicht 03.07.2026 20:19:29
  • Zuletzt bearbeitet 07.07.2026 18:16:35

Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.

  • EPSS 0.49%
  • Veröffentlicht 03.07.2026 20:19:28
  • Zuletzt bearbeitet 06.07.2026 19:17:00

Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.