GO-2026-6074None▾ SunlitGitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
code.gitea.io/gitea < 1.26.0Upgrade to a patched release:
code.gitea.io/gitea 1.26.0Connected by shared product, vendor, weakness, or advisory.
GHSA-rjvx-x5h2-6px5MediumGitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions
CVE-2025-68939High· 8.2Gitea allows attackers to add attachments with forbidden file extensions
CVE-2026-34966High· 7.6Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default …
CVE-2026-56657Medium· 6.2Gitea SSH Key Parser Denial of Service
CVE-2026-58314High· 7.7Gitea: Two SSRF findings
CVE-2026-56443Medium· 4.3Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / …