在仓库主页( )上,个人访问令牌的范围限制存在绕过漏洞,可导致私有仓库内容被泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Gitea | Gitea Open Source Git Server | < 1.27.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Gitea | Gitea Open Source Git Server | 0 ~ 1.27.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58442 | Repository migration SSRF via multi-answer DNS allow-list bypass | |
| CVE-2026-58507 | Private Repository Existence Disclosure via go-get Meta Endpoint | |
| CVE-2026-58511 | Webhook Authorization Header Returned in Plaintext via API | |
| CVE-2026-24059 | Gitea runner registration-token GET endpoint performs a write under a read-only token scop | |
| CVE-2026-24791 | Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes | |
| CVE-2026-58433 | Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setti | |
| CVE-2026-58508 | Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | |
| CVE-2026-55986 | Email Management API Bypasses ManageCredentials Feature Restrictions | |
| CVE-2026-59765 | SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud M | |
| CVE-2026-58443 | Public-only repository tokens can update private PR head branches | |
| CVE-2026-58445 | Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API | |
| CVE-2026-58441 | SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL | |
| CVE-2026-58440 | Webhooks created by a collaborator keep firing after their repo access is revoked → ongoin | |
| CVE-2026-58439 | Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag | |
| CVE-2026-58438 | Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment | |
| CVE-2026-58437 | Repository Visibility Manipulation via Git Push Options | |
| CVE-2026-58436 | ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests | |
| CVE-2026-58435 | Gitea LFS Deploy-Key Privilege Escalation | |
| CVE-2026-58434 | Private Repository Metadata Remains Accessible After Access Revocation | |
| CVE-2026-58432 | Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect P |
Showing top 20 of 47 CVEs. View all on vendor page → →
No comments yet