Multiple vulnerabilities in Gitea (CVE not specified) can be exploited by a remote attacker to disclose information, resulting in a CVSS base score of 7.6 (High). The affected versions are all releases of the open-source Gitea software prior to version 1.27.0. A mitigation is available, and users should upgrade to Gitea 1.27.0 or later.
[WID-SEC-2026-2678] Gitea: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen CVSS Base Score 7.6 (hoch) CVSS Temporal Score 6.6 (mittel) Remoteangriff ja Datum 05.08.2026 Stand 06.08.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung Gitea ist ein quelloffener Github-Klon. Produkte 05.08.2026 Open Source Gitea <1.27.0 Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben