2026 CVE Vulnerabilities

57,913 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27779HIGH7.5Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing sp...
CVE-2026-27775HIGH8.8Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allo...
CVE-2026-27771HIGH8.2Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which c...
CVE-2026-27761MEDIUM4.3Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope ...
CVE-2026-27660HIGH7.5Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permissio...
CVE-2026-27657HIGH7.5Gitea versions before 1.25.5 allow a user to change another user's primary email address.
CVE-2026-26307HIGH7.5Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume serve...
CVE-2026-26292CRITICAL9.8Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing ...
CVE-2026-26247CRITICAL9.1Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowi...
CVE-2026-26232CRITICAL9.1Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during...
CVE-2026-26231HIGH8.5Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to...
CVE-2026-25782MEDIUM5.3Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the requ...
CVE-2026-25779MEDIUM6.1Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect...
CVE-2026-25718CRITICAL9.1Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processi...
CVE-2026-25714MEDIUM4.3Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization...
CVE-2026-25712HIGH7.5Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and ...
CVE-2026-25038HIGH7.5Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
CVE-2026-24690HIGH7.5Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
CVE-2026-24451HIGH7.5Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing ...
CVE-2026-22874CRITICAL9.6Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
CVE-2026-22555HIGH8.1Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCrea...
CVE-2026-22547CRITICAL9.1Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited templa...
CVE-2026-20909MEDIUM5.3Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
CVE-2026-20896CRITICAL9.8Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any sour...
CVE-2026-20779HIGH7.1Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be ac...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now