VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,319 CVE recordsPage 428 of 1288 · EPSS data 2026.08.12
ReviewCritical
CVE-2026-26292

Gitea Gitea Open Source Git Server

Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-26247

Gitea Gitea Open Source Git Server

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-26231

Gitea Gitea Open Source Git Server

Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-25718

Gitea Gitea Open Source Git Server

Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-25038

Gitea Gitea Open Source Git Server

CVE-2026-25038 affects Gitea Gitea Open Source Git Server. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24451

Gitea Gitea Open Source Git Server

Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-22555

Gitea Gitea Open Source Git Server

Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-22547

Gitea Gitea Open Source Git Server

Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or object format values.

The CVSS severity warrants an early asset and exposure review.
PriorityCritical
CVE-2026-20896

Gitea Gitea Open Source Git Server

Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewHigh
CVE-2026-20779

Gitea Gitea Open Source Git Server

Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-20706

Gitea Gitea Open Source Git Server

Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.

The CVSS severity warrants an early asset and exposure review.