Vulnerabilities in Gitea

64 results
Vexday analysis

Gitea apresenta perfil de risco moderado com 63 vulnerabilidades catalogadas, sendo 16 críticas (CVSS≥9) e 41 publicadas nos últimos 90 dias, indicando exposição a descobertas recentes. Apesar da ausência de exploração ativa registrada (KEV=0), a fraqueza dominante CWE-284 (controle de acesso inadequado) representa vetor de risco estrutural que demanda revisão de permissões e segmentação. A velocidade de publicação de vulnerabilidades sugere monitoramento contínuo de patches.

CVE-2026-26232CRITICALGitea OAuth2 authorization codes lack expiry and reuse enforcementEPSS 0.4%CVE-2026-26247CRITICALGitea OAuth2 PKCE S256 challenges are not enforced during token exchangeEPSS 0.4%CVE-2026-22547CRITICALGitea repository creation accepts invalid field valuesEPSS 0.4%CVE-2026-28705MEDIUMGitea repository dumps write release assets using unsafe path namesEPSS 0.4%CVE-2026-27761MEDIUMGitea repository feeds bypass API token scope enforcementEPSS 0.4%CVE-2026-20800MEDIUMNotification API Leaks Private Repository Issue Titles After Collaborator Permission RevocationEPSS 0.4%CVE-2025-69413MEDIUMIn Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.EPSS 0.4%CVE-2025-68938MEDIUMGitea before 1.25.2 mishandles authorization for deletion of releases.EPSS 0.4%CVE-2026-25712HIGHGitea organization permission APIs expose private visibility informationEPSS 0.4%CVE-2026-24451HIGHGitea fork synchronization can expose private parent repository dataEPSS 0.4%CVE-2026-27657HIGHGitea email settings allow changing another user's primary email addressEPSS 0.3%CVE-2026-27660HIGHGitea draft releases use insufficient permission checksEPSS 0.3%CVE-2026-28744HIGHGitea Git smart HTTP bypasses repository token scopes for bearer tokensEPSS 0.3%CVE-2026-58422CRITICALImproper authorization on OAuth sign-in callback silently re-enables administrator-disabled accountsEPSS 0.3%CVE-2026-28737HIGHGitea 3D file viewer allows stored XSS through glTF extensionsRequiredEPSS 0.3%CVE-2026-20883MEDIUMGitea Stopwatch API Missing Authorization Check Leads to Post-Revocation Information DisclosureEPSS 0.3%CVE-2025-68943MEDIUMGitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.EPSS 0.3%CVE-2025-68945MEDIUMIn Gitea before 1.21.2, an anonymous user can visit a private user's project.EPSS 0.3%CVE-2026-25714MEDIUMGitea user organization API bypasses public-only token filteringEPSS 0.3%CVE-2026-58421HIGHUnauthenticated ReDoS via CODEOWNERS pattern matching allows denial of serviceEPSS 0.3%