当在 配置项中设置 时,Gitea 会将新创建的仓库默认设为私有仓库。然而,在通过推送(push)操作创建的空仓库上,post-receive 钩子(hook)仍然会应用 的推送选项。这使得任何具备创建仓库权限的用户能够将其新建的仓库设为公开状态,从而违反实例的安全策略。默认配置不受此问题影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96399 | Gitea denial of service through external issue tracker patterns | |
| CVE-2026-97626 | Gitea profile feed disclosure bypassing user visibility | |
| CVE-2026-96594 | Gitea repository media API stored XSS | |
| CVE-2026-104633 | Gitea migration memory exhaustion from zero page size | |
| CVE-2026-101023 | Gitea OAuth2 refresh token grant accepts access tokens | |
| CVE-2026-105267 | Gitea tag delete route deletes releases without release permission | |
| CVE-2026-105268 | Gitea issue attachment API allows changing comment attachments | |
| CVE-2026-86684 | Gitea push mirror local path check uses the repository owner | |
| CVE-2026-97208 | Gitea push mirror API bypass of DISABLE_NEW_PUSH policy | |
| CVE-2026-73278 | Gitea WebAuthn bypass during OAuth and OIDC sign-in | |
| CVE-2026-79960 | Gitea deploy key pushes acting as the repository owner | |
| CVE-2026-70357 | Gitea repository migration SSRF through DNS rebinding | |
| CVE-2026-96580 | Gitea Actions memory exhaustion through large static matrices | |
| CVE-2026-96589 | Gitea private repository access retained after rejected transfer | |
| CVE-2026-96400 | Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS | |
| CVE-2026-94205 | Gitea fork workflow approval bypass through maintainer-triggered events | |
| CVE-2026-96404 | Gitea installer authentication bypass for existing accounts | |
| CVE-2026-104626 | Gitea fork workflow job revival through later approval | |
| CVE-2026-104632 | Gitea fork workflow approval bypass through cancel and rerun | |
| CVE-2026-104636 | Gitea SSRF through Git HTTP redirects in mirrors and fetches |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet