Vulnerabilities in Gitea

64 results
Vexday analysis

Gitea apresenta perfil de risco moderado com 63 vulnerabilidades catalogadas, sendo 16 críticas (CVSS≥9) e 41 publicadas nos últimos 90 dias, indicando exposição a descobertas recentes. Apesar da ausência de exploração ativa registrada (KEV=0), a fraqueza dominante CWE-284 (controle de acesso inadequado) representa vetor de risco estrutural que demanda revisão de permissões e segmentação. A velocidade de publicação de vulnerabilidades sugere monitoramento contínuo de patches.

CVE-2026-24690HIGHGitea pull-request branch updates use insufficient permission checksEPSS 0.3%CVE-2026-34966HIGHGitea prior to 1.27.0 SSRF via Migration URI Fetch BypassEPSS 0.3%CVE-2026-58423HIGHLFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositoriesEPSS 0.3%CVE-2026-22555HIGHGitea organization forks can expose organization secrets without create permissionEPSS 0.3%CVE-2026-20888MEDIUMGitea Pull Requests Auto-Merge: Read-Only Users Can Cancel Scheduled Auto-Merge via Web Endpoint (Authorization Bypass)EPSS 0.3%CVE-2025-68939HIGHGitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.EPSS 0.3%CVE-2026-58419HIGHNotification API leaks private issue metadata after access revocationEPSS 0.3%CVE-2026-26231HIGHGitea maintainer-edit permissions allow unauthorized commits to readable repositoriesEPSS 0.3%CVE-2026-20909MEDIUMGitea tracked-time list endpoint has insufficient permission checksEPSS 0.3%CVE-2026-25782MEDIUMGitea tracked-time deletion can target entries from another issueEPSS 0.3%CVE-2026-27783MEDIUMGitea issue-template APIs bypass repository unit authorizationEPSS 0.3%CVE-2026-20904MEDIUMGitea: Broken access control in OpenID visibility toggle enables cross-user visibility changesEPSS 0.3%CVE-2026-28740HIGHGitea LFS object reuse bypasses Code-unit authorizationEPSS 0.3%CVE-2026-58053CRITICALGitea act_runner - Container Hardening Bypass via Workflow Container OptionsEPSS 0.3%CVE-2025-68944MEDIUMGitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.EPSS 0.3%CVE-2025-68940LOWIn Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.EPSS 0.3%CVE-2026-25779MEDIUMGitea redirect handling permits open redirects through backslash pathsEPSS 0.2%CVE-2026-58418MEDIUMSSRF via HTTP Redirect in Repository MigrationEPSS 0.2%CVE-2025-68941MEDIUMGitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.EPSS 0.2%CVE-2026-0798LOWGitea Release Email Notifications Leak Private Repository Release Details After Access RevocationEPSS 0.2%