Vulnerabilities in Gitea
111 resultsVexday analysis
Gitea apresenta perfil de risco moderado com 63 vulnerabilidades catalogadas, sendo 16 críticas (CVSS≥9) e 41 publicadas nos últimos 90 dias, indicando exposição a descobertas recentes. Apesar da ausência de exploração ativa registrada (KEV=0), a fraqueza dominante CWE-284 (controle de acesso inadequado) representa vetor de risco estrutural que demanda revisão de permissões e segmentação. A velocidade de publicação de vulnerabilidades sugere monitoramento contínuo de patches.
CVE-2025-68946MEDIUMIn Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.EPSS 0.2%CVE-2025-68942MEDIUMGitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.EPSS 0.2%CVE-2026-58424HIGHPermanent Fork PR Workflow Approval Gate BypassEPSS 0.2%CVE-2026-58426CRITICALGitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state writeEPSS 0.2%CVE-2026-55984—Null Pointer Dereference in AddTime API Causes Authenticated Denial of ServiceEPSS —CVE-2026-58435—Gitea LFS Deploy-Key Privilege EscalationEPSS —CVE-2026-58511LOWWebhook Authorization Header Returned in Plaintext via APIEPSS —CVE-2026-55987—OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)EPSS —CVE-2026-58441—SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURLEPSS —CVE-2026-58439—Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval FlagEPSS —CVE-2026-58510MEDIUMGHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->privateEPSS —CVE-2026-54481—Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)EPSS —CVE-2026-23603—Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claimEPSS —CVE-2026-59763MEDIUMUnbounded Arch package file metadata can cause resource amplification in Gitea package uploadsEPSS —CVE-2026-58416HIGHFork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)EPSS —CVE-2026-58438—Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot accessEPSS —CVE-2026-57894—Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository ExfiltrationEPSS —CVE-2026-58443—Public-only repository tokens can update private PR head branchesEPSS —CVE-2026-58437—Repository Visibility Manipulation via Git Push OptionsEPSS —CVE-2026-58420—Local File Inclusion via file:// URI in Migration RestoreEPSS —