CVE-2026-26232
- EPSS 0.38%
- Veröffentlicht 03.07.2026 20:19:34
- Zuletzt bearbeitet 07.07.2026 18:16:37
Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.
CVE-2026-26247
- EPSS 0.38%
- Veröffentlicht 03.07.2026 20:19:34
- Zuletzt bearbeitet 07.07.2026 18:16:37
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
CVE-2026-25779
- EPSS 0.25%
- Veröffentlicht 03.07.2026 20:19:33
- Zuletzt bearbeitet 07.07.2026 18:16:36
Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect_to values.
CVE-2026-25038
- EPSS 0.42%
- Veröffentlicht 03.07.2026 20:19:32
- Zuletzt bearbeitet 07.07.2026 18:16:36
Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
CVE-2026-25712
- EPSS 0.35%
- Veröffentlicht 03.07.2026 20:19:32
- Zuletzt bearbeitet 07.07.2026 18:16:36
Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.
CVE-2026-25714
- EPSS 0.33%
- Veröffentlicht 03.07.2026 20:19:32
- Zuletzt bearbeitet 07.07.2026 18:16:36
Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.
CVE-2026-22555
- EPSS 0.31%
- Veröffentlicht 03.07.2026 20:19:30
- Zuletzt bearbeitet 06.07.2026 21:16:54
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.
CVE-2026-20779
- EPSS 0.4%
- Veröffentlicht 03.07.2026 20:19:29
- Zuletzt bearbeitet 07.07.2026 18:16:35
Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.
CVE-2026-20909
- EPSS 0.29%
- Veröffentlicht 03.07.2026 20:19:29
- Zuletzt bearbeitet 07.07.2026 18:16:35
Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
CVE-2026-20706
- EPSS 0.49%
- Veröffentlicht 03.07.2026 20:19:28
- Zuletzt bearbeitet 06.07.2026 19:17:00
Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.