Gitea 推送镜像 API 在检查是否允许使用本地文件系统路径时,仅验证了仓库所有者(repository owner)的权限,而未验证实际发起请求的用户。在配置了 的 Gitea 实例中,若仓库所有者拥有使用本地路径的权限,则即使仓库管理员(repository administrator)本身无权导入本地路径,该管理员也可以通过推送镜像功能,将一个推送镜像指向服务器上的一个本地路径。随后,Gitea 会以 Gitea 进程自身的权限,将该仓库的引用(refs)推送到该路径上已存在的 Git 仓库中。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96399 | Gitea denial of service through external issue tracker patterns | |
| CVE-2026-97626 | Gitea profile feed disclosure bypassing user visibility | |
| CVE-2026-96594 | Gitea repository media API stored XSS | |
| CVE-2026-104633 | Gitea migration memory exhaustion from zero page size | |
| CVE-2026-101023 | Gitea OAuth2 refresh token grant accepts access tokens | |
| CVE-2026-105267 | Gitea tag delete route deletes releases without release permission | |
| CVE-2026-105268 | Gitea issue attachment API allows changing comment attachments | |
| CVE-2026-89182 | Gitea push-to-create bypass of FORCE_PRIVATE policy | |
| CVE-2026-97208 | Gitea push mirror API bypass of DISABLE_NEW_PUSH policy | |
| CVE-2026-73278 | Gitea WebAuthn bypass during OAuth and OIDC sign-in | |
| CVE-2026-79960 | Gitea deploy key pushes acting as the repository owner | |
| CVE-2026-70357 | Gitea repository migration SSRF through DNS rebinding | |
| CVE-2026-96580 | Gitea Actions memory exhaustion through large static matrices | |
| CVE-2026-96589 | Gitea private repository access retained after rejected transfer | |
| CVE-2026-96400 | Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS | |
| CVE-2026-94205 | Gitea fork workflow approval bypass through maintainer-triggered events | |
| CVE-2026-96404 | Gitea installer authentication bypass for existing accounts | |
| CVE-2026-104626 | Gitea fork workflow job revival through later approval | |
| CVE-2026-104632 | Gitea fork workflow approval bypass through cancel and rerun | |
| CVE-2026-104636 | Gitea SSRF through Git HTTP redirects in mirrors and fetches |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet