-Infinity
0

Gitea GiteaGitea prior to 1.27.0 SSRF via Migration URI Fetch Bypass

Risk 48
Severity
8.3
First published (updated )

BleepingComputerHackers exploit critical auth bypass in Gitea Docker image

First published (updated )

Critical Gitea Flaw Under Active Exploitation, Researchers Warn

First published (updated )
Social
reddit

Exploitarium coverage update: CVE-2026-20896 Gitea probing confirmed + 10 new rules added

First published (updated )
Social
reddit

Gitea GiteaGitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

Risk 68
Severity
9.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Gitea GiteaGitea LFS object reuse bypasses Code-unit authorization

Risk 48
Severity
7.1
First published (updated )

Gitea GiteaGitea repository dumps write release assets using unsafe path names

Risk 27
Severity
5.3
First published (updated )

Gitea GiteaGitea pre-receive hook permission cache allows full repository write access

Risk 79
Severity
8.8
First published (updated )

Gitea GiteaGitea forwarded-proto handling allows public URL spoofing

Risk 43
Severity
7.5
First published (updated )

Gitea GiteaGitea pre-receive hook can miss branch-protection checks after scanner errors

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Gitea GiteaGitea Composer package source links use insufficient permission checks

Risk 54
Severity
8.2
First published (updated )

Gitea GiteaGitea repository feeds bypass API token scope enforcement

Risk 22
Severity
4.3
First published (updated )

Gitea GiteaGitea draft releases use insufficient permission checks

Risk 43
Severity
7.5
First published (updated )

Gitea GiteaGitea git grep search lacks a timeout

Risk 43
Severity
7.5
First published (updated )

Gitea GiteaGitea LFS mirror synchronization bypasses migration HTTP transport restrictions

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Gitea GiteaGitea email settings allow changing another user's primary email address

Risk 43
Severity
7.5
First published (updated )

Gitea GiteaGitea OAuth2 PKCE S256 challenges are not enforced during token exchange

Risk 66
Severity
9.1
First published (updated )

Gitea GiteaGitea OAuth2 authorization codes lack expiry and reuse enforcement

Risk 66
Severity
9.1
First published (updated )

Gitea GiteaGitea tracked-time deletion can target entries from another issue

Risk 27
Severity
5.3
First published (updated )

Gitea GiteaGitea template repository generation mishandles symlinked paths

Risk 66
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Gitea GiteaGitea private organization labels are visible to unauthorized users

Risk 43
Severity
7.5
First published (updated )

Gitea GiteaGitea organization permission APIs expose private visibility information

Risk 43
Severity
7.5
First published (updated )

Gitea GiteaGitea webhook and migration allow-list filtering permits SSRF

Risk 68
Severity
9.6
First published (updated )

Gitea GiteaGitea pull-request branch updates use insufficient permission checks

Risk 43
Severity
7.5
First published (updated )

Gitea GiteaGitea fork synchronization can expose private parent repository data

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Gitea GiteaGitea repository creation accepts invalid field values

Risk 66
Severity
9.1
First published (updated )

Gitea GiteaGitea tracked-time list endpoint has insufficient permission checks

Risk 27
Severity
5.3
First published (updated )

Gitea GiteaGitea TOTP single-use enforcement defect allows OTP replay

Risk 47
Severity
7.1
First published (updated )

Gitea act_runnerGitea act_runner - Container Hardening Bypass via Workflow Container Options

Risk 82
Severity
9.4
First published (updated )

Gitea GiteaGitea does not properly validate repository ownership when linking attachments to releases. An attac…

Risk 40
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203