Gitea

Gitea

154 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 13.08.2026 16:44:39
  • Zuletzt bearbeitet 26.08.2026 16:53:48

Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)

  • EPSS 0.16%
  • Veröffentlicht 13.08.2026 16:44:38
  • Zuletzt bearbeitet 26.08.2026 16:53:48

Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

  • EPSS 0.38%
  • Veröffentlicht 13.08.2026 16:44:38
  • Zuletzt bearbeitet 26.08.2026 16:53:48

Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

  • EPSS 0.31%
  • Veröffentlicht 05.08.2026 20:28:57
  • Zuletzt bearbeitet 08.10.2026 16:17:13

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get with...

  • EPSS 0.19%
  • Veröffentlicht 03.07.2026 20:54:53
  • Zuletzt bearbeitet 06.07.2026 18:17:26

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

  • EPSS 0.34%
  • Veröffentlicht 03.07.2026 20:54:52
  • Zuletzt bearbeitet 06.07.2026 18:18:46

Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

  • EPSS 0.31%
  • Veröffentlicht 03.07.2026 20:54:52
  • Zuletzt bearbeitet 06.07.2026 18:18:46

LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

  • EPSS 0.2%
  • Veröffentlicht 03.07.2026 20:54:52
  • Zuletzt bearbeitet 06.07.2026 18:18:46

Permanent Fork PR Workflow Approval Gate Bypass

  • EPSS 0.24%
  • Veröffentlicht 03.07.2026 20:54:51
  • Zuletzt bearbeitet 06.07.2026 18:18:46

SSRF via HTTP Redirect in Repository Migration

  • EPSS 0.33%
  • Veröffentlicht 03.07.2026 20:54:51
  • Zuletzt bearbeitet 06.07.2026 18:18:46

Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service