令牌权限绕过问题:在受限可见性所有者(包括“仓库”和“软件包”类别)的情况下,public-only 作用域被绕过——此为 CVE-2026-25714 漏洞及 PR #37118 修复后的残余问题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Gitea | Gitea Open Source Git Server | ≤ 1.26.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Gitea | Gitea Open Source Git Server | 0 ~ 1.26.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58443 | Public-only repository tokens can update private PR head branches | |
| CVE-2026-58507 | Private Repository Existence Disclosure via go-get Meta Endpoint | |
| CVE-2026-58511 | Webhook Authorization Header Returned in Plaintext via API | |
| CVE-2026-24059 | Gitea runner registration-token GET endpoint performs a write under a read-only token scop | |
| CVE-2026-24791 | Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes | |
| CVE-2026-58433 | Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setti | |
| CVE-2026-58508 | Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | |
| CVE-2026-55986 | Email Management API Bypasses ManageCredentials Feature Restrictions | |
| CVE-2026-59765 | SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud M | |
| CVE-2026-58444 | Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/ | |
| CVE-2026-58445 | Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API | |
| CVE-2026-58442 | Repository migration SSRF via multi-answer DNS allow-list bypass | |
| CVE-2026-58441 | SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL | |
| CVE-2026-58440 | Webhooks created by a collaborator keep firing after their repo access is revoked → ongoin | |
| CVE-2026-58439 | Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag | |
| CVE-2026-58438 | Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment | |
| CVE-2026-58437 | Repository Visibility Manipulation via Git Push Options | |
| CVE-2026-58436 | ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests | |
| CVE-2026-58435 | Gitea LFS Deploy-Key Privilege Escalation | |
| CVE-2026-58434 | Private Repository Metadata Remains Accessible After Access Revocation |
Showing top 20 of 47 CVEs. View all on vendor page → →
No comments yet