[Git][security-tracker-team/security-tracker][master] auto-nfu: Add rule for Gitea
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Aug 14 08:40:00 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
930e1803 by Moritz Muehlenhoff at 2026-08-14T09:39:37+02:00
auto-nfu: Add rule for Gitea
- - - - -
2 changed files:
- data/CVE/list
- data/packages/nfu.yaml
Changes:
=====================================
data/CVE/list
=====================================
@@ -918,9 +918,9 @@ CVE-2026-61962 (Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6
CVE-2026-61960 (Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8 ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-59765 (SSRF via Migration Asset Downloads Bypasses hostmatcher \u2014 Reads I ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-59763 (Unbounded Arch package file metadata can cause resource amplification ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-59507 (CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive ...)
TODO: check
CVE-2026-59506 (CWE-306: Missing Authentication for Critical Function)
@@ -942,83 +942,83 @@ CVE-2026-59499 (CWE-200: Exposure of Sensitive Information to an Unauthorized Ac
CVE-2026-59109 (SQL injection in the Zalktis accounting application via trading-partne ...)
TODO: check
CVE-2026-58511 (Webhook Authorization Header Returned in Plaintext via API)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58510 (GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo p ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58508 (Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + mi ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58507 (Private Repository Existence Disclosure via go-get Meta Endpoint)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58445 (Cross-repository label-ID enumeration oracle via unscoped DeleteIssueL ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58444 (Personal access token scope enforcement bypass on the repository home ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58443 (Public-only repository tokens can update private PR head branches)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58442 (Repository migration SSRF via multi-answer DNS allow-list bypass)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58441 (SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58440 (Webhooks created by a collaborator keep firing after their repo access ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58439 (Branch Protection Bypass via PR Retargeting Preserves Stale `official` ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58438 (Cross-repository IDOR in issue-dependency removal lets an attacker tam ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58437 (Repository Visibility Manipulation via Git Push Options)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58436 (ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauth ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58435 (Gitea LFS Deploy-Key Privilege Escalation)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58434 (Private Repository Metadata Remains Accessible After Access Revocation)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58433 (Team-repository linking endpoint bypasses the RepoAdminChangeTeamAcces ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58432 (Missing Authorization and Authorization Bypass Through User-Controlled ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58431 (Public-only API token restriction is not enforced on team API routes)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58429 (Public-Only Personal access tokens scope bypass in Organization and Pe ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58428 (Release attachment extension allowlist bypass via web release edit for ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58427 (Private org member list leaked via /members API endpoint \u2014 incomp ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58425 (OAuth token introspection returns metadata of tokens issued to other c ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58420 (Local File Inclusion via file:// URI in Migration Restore)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58417 (REST API exposes organization membership of private organizations to p ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58416 (Fork-PR Actions task can read a third private repository via the colla ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-58314 (Two SSRF findings in Gitea 1.26.2)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-57897 (Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-57894 (Repository Migration Follows Git HTTP Redirects After URL Allow/Block ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-57886 (Cross-repository issue/comment attachment re-linking can expose privat ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-56755 (Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concaten ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-56750 (Gitea Remember-Me Token Theft Not Invalidating Attacker Session)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-56657 (Gitea SSH Key Parser Denial of Service)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-56654 (Privilege Escalation via Access Token Scope Escalation in API)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-56443 (Token public-only scope bypassed on Limited-visibility owners (Reposit ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-55987 (OAuth2 sign-in reactivates an administrator-deactivated account on aut ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-55986 (Email Management API Bypasses ManageCredentials Feature Restrictions)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-55984 (Null Pointer Dereference in AddTime API Causes Authenticated Denial of ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-55982 (OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API T ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-55402 (CVE-2026-55402 is an out of bounds read vulnerability in Secure Access ...)
NOT-FOR-US: Absolute Software
CVE-2026-55401 (CVE-2026-55401 is a null dereference vulnerability on the load-balanci ...)
@@ -1026,9 +1026,9 @@ CVE-2026-55401 (CVE-2026-55401 is a null dereference vulnerability on the load-b
CVE-2026-55400 (CVE-2026-55400 is an integer underflow in Secure Access servers prior ...)
NOT-FOR-US: Absolute Software
CVE-2026-54481 (Internal API HTTP client hardcodes InsecureSkipVerify:true with no con ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-50105 (RSS/Atom feed handlers bypass API-token scope & public-only confinemen ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-49857 (auth-fetch-mcp is an MCP server that lets AI assistants fetch content ...)
TODO: check
CVE-2026-49856 (@jshookmcp/jshook is an MCP server that gives AI agents tools for Java ...)
@@ -1040,7 +1040,7 @@ CVE-2026-49820 (Probo is a self-hostable governance, risk, and compliance (GRC)
CVE-2026-45819 (baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instea ...)
TODO: check
CVE-2026-42931 (Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-3639 (The PPWP \u2013 Password Protect Pages plugin for WordPress is vulnera ...)
NOT-FOR-US: WordPress plugin
CVE-2026-28189 (Unauthenticated Arbitrary File Deletion in Participants Database <= 2. ...)
@@ -1122,11 +1122,11 @@ CVE-2026-27380 (Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versi
CVE-2026-27345 (Unauthenticated Broken Access Control in Taxi Booking Manager for WooC ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-24791 (Public-only tokens bypass private-resource restrictions on `/api/v1/us ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-24059 (The GET /api/v1/user/actions/runners/registration-token endpoint (and ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-23603 (Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC pictu ...)
- TODO: check
+ NOT-FOR-US: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
CVE-2026-21832 (HCL AION is affected by a vulnerability where indirect prompt injectio ...)
NOT-FOR-US: HCL
CVE-2026-19744 (Cross-site Scripting in the Markdown renderer in maalfer Pentestify be ...)
=====================================
data/packages/nfu.yaml
=====================================
@@ -117,6 +117,8 @@
cna: GV
- reason: Genetec
cna: Genetec
+- reason: Gitea (used to be packaged in the Debian archive as src:gitea, but never in a stable release)
+ cna: Gitea
- reason: Github Enterprise Server
cna: GitHub_P
- reason: Google devices
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/930e18030b1b0c194608d09abefc8c3b5d5f71ef
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/930e18030b1b0c194608d09abefc8c3b5d5f71ef
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/56faf581/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list