CVE-2025-68939High· 8.2▾ TwilightGitea allows attackers to add attachments with forbidden file extensions
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.
code.gitea.io/giteaRefer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34966MediumGitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
GO-2026-6074NoneGitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
CVE-2026-59765MediumGitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
CVE-2026-58429Medium· 4.9Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CVE-2026-55984Low· 2.7Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
CVE-2026-58435Medium· 5.4Gitea LFS Deploy-Key Privilege Escalation