Gitea API 端点 会将大小最多为 1 KiB 且直接存储在 Git 中(而非 LFS)的文件写入响应,但未添加 Gitea 用于用户内容所通常使用的 和 头部。因此,提交到仓库中的 HTML 文件会在浏览器中按照 Gitea 的源站进行渲染。任何具有仓库推送权限的用户,都可以诱使受害者在浏览器中打开该媒体文件 URL,从而在受害者的会话中执行 JavaScript 代码,并以受害者的权限执行相关操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96399 | Gitea denial of service through external issue tracker patterns | |
| CVE-2026-97626 | Gitea profile feed disclosure bypassing user visibility | |
| CVE-2026-104633 | Gitea migration memory exhaustion from zero page size | |
| CVE-2026-101023 | Gitea OAuth2 refresh token grant accepts access tokens | |
| CVE-2026-105267 | Gitea tag delete route deletes releases without release permission | |
| CVE-2026-105268 | Gitea issue attachment API allows changing comment attachments | |
| CVE-2026-89182 | Gitea push-to-create bypass of FORCE_PRIVATE policy | |
| CVE-2026-86684 | Gitea push mirror local path check uses the repository owner | |
| CVE-2026-97208 | Gitea push mirror API bypass of DISABLE_NEW_PUSH policy | |
| CVE-2026-73278 | Gitea WebAuthn bypass during OAuth and OIDC sign-in | |
| CVE-2026-79960 | Gitea deploy key pushes acting as the repository owner | |
| CVE-2026-70357 | Gitea repository migration SSRF through DNS rebinding | |
| CVE-2026-96580 | Gitea Actions memory exhaustion through large static matrices | |
| CVE-2026-96589 | Gitea private repository access retained after rejected transfer | |
| CVE-2026-96400 | Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS | |
| CVE-2026-94205 | Gitea fork workflow approval bypass through maintainer-triggered events | |
| CVE-2026-96404 | Gitea installer authentication bypass for existing accounts | |
| CVE-2026-104626 | Gitea fork workflow job revival through later approval | |
| CVE-2026-104632 | Gitea fork workflow approval bypass through cancel and rerun | |
| CVE-2026-104636 | Gitea SSRF through Git HTTP redirects in mirrors and fetches |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet