Vulnerabilities
Vulnerable Software
Gitea:  >> Gitea  >> 1.22.2  Security Vulnerabilities
In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.
CVSS Score
5.3
EPSS Score
0.004
Published
2026-01-01
Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.
CVSS Score
8.2
EPSS Score
0.003
Published
2025-12-26
In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.
CVSS Score
3.1
EPSS Score
0.003
Published
2025-12-26
Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.
CVSS Score
4.9
EPSS Score
0.003
Published
2025-12-26
Gitea before 1.25.2 mishandles authorization for deletion of releases.
CVSS Score
4.3
EPSS Score
0.004
Published
2025-12-26


Contact Us

Shodan ® - All rights reserved