« Volver al listado

Gitea

Gitea: vulnerabilidades y CVE

Gitea tiene 97 vulnerabilidades publicadas, 63 de ellas en los últimos 12 meses. 24 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE97
Últimos 12 meses63
Críticas24
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-60004Crítica (9.8)24%⚠ Explotación activa26 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-60004Crítica (9.8)24%⚠ Explotación activa26 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
CVE-2026-59763Media (4.3)0.41%—13 ago 2026
Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
CVE-2026-58510Media (4.3)0.33%—13 ago 2026
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
CVE-2026-58508Crítica (9.1)0.48%—13 ago 2026
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
CVE-2026-58435Media (5.4)0.29%—13 ago 2026
Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-58432Media (5.9)0.43%—13 ago 2026
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
CVE-2026-58314Alta (7.7)0.40%—13 ago 2026
Two SSRF findings in Gitea 1.26.2
CVE-2026-56750Crítica (9.1)0.48%—13 ago 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
CVE-2026-56657Media (6.2)0.17%—13 ago 2026
Gitea SSH Key Parser Denial of Service
CVE-2026-34966Alta (8.3)0.39%—5 ago 2026
Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that…
CVE-2026-58426Crítica (9.6)0.30%—3 jul 2026
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
CVE-2026-28744Alta (8.1)0.45%—3 jul 2026
Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.
CVE-2026-28740Alta (7.1)0.32%—3 jul 2026
Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.
CVE-2026-28737Alta (8.7)0.43%—3 jul 2026
Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer.
CVE-2026-28705Media (5.3)0.45%—3 jul 2026
Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.
CVE-2026-28699Alta (8.1)0.55%—3 jul 2026
Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.
CVE-2026-27783Media (4.3)0.34%—3 jul 2026
Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.
CVE-2026-27780Crítica (9.8)0.64%—3 jul 2026
Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.
CVE-2026-27779Alta (7.5)0.58%—3 jul 2026
Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
CVE-2026-27775Alta (8.8)0.52%—3 jul 2026
Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-edit grant to be reused for other refs and escalate to full repository…
CVE-2026-27771Alta (8.2)1.4%—3 jul 2026
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
CVE-2026-27761Media (4.3)0.37%—3 jul 2026
Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.
CVE-2026-27660Alta (7.5)0.45%—3 jul 2026
Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.
CVE-2026-27657Alta (7.5)0.45%—3 jul 2026
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
CVE-2026-26307Alta (7.5)0.63%—3 jul 2026
Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.
CVE-2026-26292Crítica (9.8)0.65%—3 jul 2026
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
CVE-2026-26247Crítica (9.1)0.50%—3 jul 2026
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
CVE-2026-26232Crítica (9.1)0.50%—3 jul 2026
Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.
CVE-2026-26231Alta (8.5)0.35%—3 jul 2026
Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.
CVE-2026-25782Media (5.3)0.39%—3 jul 2026
Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application24
  2. T1210 Exploitation of Remote Services10
  3. T1005 Data from Local System8
  4. T1078 Valid Accounts8
  5. T1090 Proxy3
  6. T1565.002 Transmitted Data Manipulation3

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Gitea