Gitea 的仓库迁移和拉取镜像的出口检查可能存在绕过风险:当主机名返回多个 DNS 解析结果时,系统校验的 IP 地址未必是后续 Git 实际连接的地址。具有低权限但可创建迁移或镜像的用户,可利用此缺陷引导服务器连接至内部服务,从而读取或写入可访问的内部 Git 或 HTTP 端点。此外,内部响应内容还可能通过迁移和镜像过程中的错误消息泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104632 | Gitea fork workflow approval bypass through cancel and rerun | |
| CVE-2026-73278 | Gitea WebAuthn bypass during OAuth and OIDC sign-in | |
| CVE-2026-79960 | Gitea deploy key pushes acting as the repository owner | |
| CVE-2026-70357 | Gitea repository migration SSRF through DNS rebinding | |
| CVE-2026-96580 | Gitea Actions memory exhaustion through large static matrices | |
| CVE-2026-96589 | Gitea private repository access retained after rejected transfer | |
| CVE-2026-96400 | Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS | |
| CVE-2026-96399 | Gitea denial of service through external issue tracker patterns | |
| CVE-2026-96404 | Gitea installer authentication bypass for existing accounts | |
| CVE-2026-104626 | Gitea fork workflow job revival through later approval | |
| CVE-2026-94205 | Gitea fork workflow approval bypass through maintainer-triggered events | |
| CVE-2026-104636 | Gitea SSRF through Git HTTP redirects in mirrors and fetches | |
| CVE-2026-101027 | Gitea migration SSRF through ALLOWED_DOMAINS address check bypass | |
| CVE-2026-95106 | Gitea review and execution mismatch through duplicate tree entries | |
| CVE-2026-95112 | Gitea issue reference parsing CPU exhaustion | |
| CVE-2026-89430 | Gitea push mirror SSRF and forced writes to internal Git hosts | |
| CVE-2026-103504 | Gitea API team demotion not applied to unit permissions | |
| CVE-2026-103667 | Gitea container registry stored XSS through blob media type | |
| CVE-2026-103059 | Gitea built-in SSH server authentication bypass through key case folding | |
| CVE-2026-103670 | Gitea trusted workflow cancellation by unapproved fork runs |
No comments yet