VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,384 CVE recordsPage 432 of 1293 · EPSS data 2026.08.12
ReviewHigh
CVE-2026-27775

Gitea Gitea Open Source Git Server

Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-edit grant to be reused for other refs and escalate to full repository write access.

The CVSS severity warrants an early asset and exposure review.
PriorityHigh
CVE-2026-27771

Gitea Gitea Open Source Git Server

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewCritical
CVE-2026-26292

Gitea Gitea Open Source Git Server

Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-26247

Gitea Gitea Open Source Git Server

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-26231

Gitea Gitea Open Source Git Server

Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-25718

Gitea Gitea Open Source Git Server

Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-25038

Gitea Gitea Open Source Git Server

CVE-2026-25038 affects Gitea Gitea Open Source Git Server. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24451

Gitea Gitea Open Source Git Server

Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.

The CVSS severity warrants an early asset and exposure review.