Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | The Gitea API endpoint for creating push mirrors (`POST /api/v1/repos/{owner}/{repo}/push_mirrors`) checked only whether mirroring was enabled and not the `[mirror] DISABLE_NEW_PUSH` setting that the web interface enforces. A repository administrator could therefore create new push mirrors on instances where the site… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | The Gitea API endpoint `GET /api/v1/repos/{owner}/{repo}/media/{filepath}` wrote files of up to 1 KiB that are stored directly in Git, not in LFS, to the response without the content type and disposition headers Gitea uses for user content. An HTML file committed to a repository was therefore rendered by the browser… | |
| Recibida | Media (5.4) | — | — | GiteaAI | 6/10/2026 | 7/10/2026 | With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | The Gitea push mirror API checked whether the repository owner, instead of the requesting user, may use local file system paths. On instances with `[security] IMPORT_LOCAL_PATHS = true`, a repository administrator who is not allowed to import local paths could add a push mirror to a local path on the server when the… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | The Gitea API routes for issue attachments (`/api/v1/repos/{owner}/{repo}/issues/{index}/assets/{attachment_id}`) also accepted attachments that belong to comments on the issue. Because the author of an issue may edit and delete the issue's attachments, a user who opened an issue could rename or delete attachments… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | The Gitea web route for deleting tags (`POST /{owner}/{repo}/tags/delete`) requires only write access to the Code unit, but shares its handler with release deletion and did not check that the target was a plain tag. A collaborator with Code write access and without Releases write access could permanently delete… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | When migrating a repository from another Gitea instance, Gitea used the page size reported in the source server's API settings to end its paginated downloads. A source that reported `max_response_items` as `0` made these loops run indefinitely and grow server memory until it was exhausted. Any user who can migrate… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the `refresh_token` grant type, but not that the token was a refresh token. An unexpired access token for the same OAuth2 application and grant could be exchanged for a new access token and refresh token. Whoever holds such an… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | When a private repository is transferred to a user who lacks access, Gitea grants that recipient temporary read access as a collaborator so they can review the repository. Rejecting or cancelling the transfer did not revoke this collaboration, so the named recipient kept persistent read access to the private… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | Gitea expanded a workflow's static `strategy.matrix` into its full Cartesian product without a size limit when creating a run, before the fork pull request approval gate applied. A user who can open a pull request from a fork could submit a small workflow file whose matrix expands to a very large number of jobs,… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the… | |
| Recibida | Media (4.3) | — | — | GiteaAI | 6/10/2026 | 7/10/2026 | With `[migrations] ALLOWED_DOMAINS` set to a matching entry such as `*` or a hostname wildcard, Gitea's migration URL validation could permit reserved and link-local addresses, such as `169.254.169.254`, even when `ALLOW_LOCALNETWORKS = false`. The local-network block list did not cover these ranges, and a hostname… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | A repository's external issue tracker regular expression containing alternating capture groups could produce invalid slice indexes when Gitea rendered issue references, causing a runtime panic that terminated the Gitea process. A user who can edit a repository's external issue tracker settings could make any later… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | When processing issue and comment bodies, Gitea scanned the entire preceding text for action keywords such as "closes" or "fixes" once per Markdown link, giving processing time quadratic in the input size. An authenticated user able to submit issue or comment content could send a crafted body of about 1 MB that keeps… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | Gitea accepted pushed Git trees containing two entries with the same name, which Git's own consistency checks reject. Gitea's web views resolved such a path to the first entry, while `git checkout`, Gitea Actions, and release archives use the last. A contributor could open a pull request whose diff and file views show… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the event rather than the pull request author. For `pull_request` activity triggered by a maintainer during ordinary triage, such as adding a label, the run was created without requiring approval, while the workflow… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created. Each synchronization passed the stored address directly to `git push`, so a name that later resolved to a blocked or internal address was still reached. A user with administrator access to… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | When a push was authenticated with a deploy key, Gitea recorded the repository owner as the pusher, so permission checks in the push hook pipeline evaluated the owner instead of the deploy key. A holder of a writable deploy key could create protected tags without being on the tag allow list and change repository… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | Gitea's OAuth2 and OpenID Connect sign-in paths do not require a WebAuthn challenge when WebAuthn is the account's only configured second factor. A party able to authenticate through the affected external identity flow can obtain a full session without the passkey verification enforced during password login. One… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | Gitea validates a repository migration hostname against its network allow and block lists before invoking Git, but the Git subprocess independently resolves the hostname when connecting. An attacker who can start a migration and control the destination's DNS can change the address between validation and connection to… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | Gitea validated the initial remote URL for push mirrors, wiki remote checks, and fetches of migrated pull request heads, but the subsequent raw Git operations followed HTTP redirects without revalidating the destination. A repository administrator using a policy-allowed endpoint that redirects could make Gitea's Git… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | Gitea Actions blocks the jobs of workflow runs from first-time fork pull request contributors until a maintainer approves the run. The rerun path only required a run to be finished and built the new attempt's jobs without considering the pending approval, so when a user with Actions write access cancelled a run that… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | A user who can open a fork pull request can place workflow content with a shared run-level concurrency group into a Gitea Actions run that is awaiting approval. When a later run in that group cancels the blocked job, the run becomes terminal while still marked as needing approval. If a maintainer later approves the… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | When a Gitea Actions run was inserted, older runs in the same workflow-level concurrency group were cancelled without checking whether the new run still needed approval. Because fork pull request runs are inserted under the base repository, a user who can open a pull request from a fork could cancel trusted… | |
| Recibida | Sin puntuar | — | — | GiteaAI | 6/10/2026 | 6/10/2026 | Gitea's container registry served blob downloads with a `Content-Type` taken from the media type declared in pushed image manifests, without a `Content-Disposition` or restrictive content security policy. A user who can push container images can publish a blob containing HTML and JavaScript with a `text/html` media… |