请求用户或组织主页( )时,若带上 或 请求头,服务器会返回该用户的活动信息流(activity feed),但未应用主页以及 和 路由中应有的可见性检查。因此,匿名用户、受限用户和非成员可以确认受限或私有用户以及私有组织的存在,并读取其个人资料详情和公开活动信息,即使配置项 已禁用,此行为仍然发生。私有仓库中的活动信息不会被包含在内。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96399 | Gitea denial of service through external issue tracker patterns | |
| CVE-2026-96594 | Gitea repository media API stored XSS | |
| CVE-2026-104633 | Gitea migration memory exhaustion from zero page size | |
| CVE-2026-101023 | Gitea OAuth2 refresh token grant accepts access tokens | |
| CVE-2026-105267 | Gitea tag delete route deletes releases without release permission | |
| CVE-2026-105268 | Gitea issue attachment API allows changing comment attachments | |
| CVE-2026-89182 | Gitea push-to-create bypass of FORCE_PRIVATE policy | |
| CVE-2026-86684 | Gitea push mirror local path check uses the repository owner | |
| CVE-2026-97208 | Gitea push mirror API bypass of DISABLE_NEW_PUSH policy | |
| CVE-2026-73278 | Gitea WebAuthn bypass during OAuth and OIDC sign-in | |
| CVE-2026-79960 | Gitea deploy key pushes acting as the repository owner | |
| CVE-2026-70357 | Gitea repository migration SSRF through DNS rebinding | |
| CVE-2026-96580 | Gitea Actions memory exhaustion through large static matrices | |
| CVE-2026-96589 | Gitea private repository access retained after rejected transfer | |
| CVE-2026-96400 | Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS | |
| CVE-2026-94205 | Gitea fork workflow approval bypass through maintainer-triggered events | |
| CVE-2026-96404 | Gitea installer authentication bypass for existing accounts | |
| CVE-2026-104626 | Gitea fork workflow job revival through later approval | |
| CVE-2026-104632 | Gitea fork workflow approval bypass through cancel and rerun | |
| CVE-2026-104636 | Gitea SSRF through Git HTTP redirects in mirrors and fetches |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet