https://github.com/bircni
23 credited records · 23 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
17Monitor | CVE-2026-97626No exploit | Gitea profile feed disclosure bypassing user visibilitygitea · gitea · CWE-200 | Medium4.3 | — | 0.2% | 4 days ago |
19Monitor | CVE-2026-97208No exploit | Gitea push mirror API bypass of DISABLE_NEW_PUSH policygitea · gitea · CWE-863 | Medium4.9 | — | 0.3% | 4 days ago |
24Monitor | CVE-2026-96594No exploit | Gitea repository media API stored XSSgitea · gitea · CWE-79 | Medium6.1 | — | 0.2% | 4 days ago |
21Monitor | CVE-2026-89182No exploit | Gitea push-to-create bypass of FORCE_PRIVATE policygitea · gitea · CWE-863 | Medium5.4 | — | 0.2% | 4 days ago |
28Monitor | CVE-2026-86684No exploit | Gitea push mirror local path check uses the repository ownergitea · gitea · CWE-863 | High7.1 | — | 0.1% | 4 days ago |
17Monitor | CVE-2026-105268No exploit | Gitea issue attachment API allows changing comment attachmentsgitea · gitea · CWE-639 | Medium4.3 | — | 0.2% | 4 days ago |
32Monitor | CVE-2026-105267No exploit | Gitea tag delete route deletes releases without release permissiongitea · gitea · CWE-732 | High8.1 | — | 0.4% | 4 days ago |
26Monitor | CVE-2026-104633No exploit | Gitea migration memory exhaustion from zero page sizegitea · gitea · CWE-400 | Medium6.5 | — | 0.4% | 4 days ago |
36Monitor | CVE-2026-101023No exploit | Gitea OAuth2 refresh token grant accepts access tokensgitea · gitea · CWE-287 | Critical9.1 | — | 0.4% | 4 days ago |
17Monitor | CVE-2026-96589No exploit | Gitea private repository access retained after rejected transfergitea · gitea · CWE-672 | Medium4.3 | — | 0.2% | 4 days ago |
30Monitor | CVE-2026-96580No exploit | Gitea Actions memory exhaustion through large static matricesgitea · gitea · CWE-400 | High7.5 | — | 0.4% | 4 days ago |
17Monitor | CVE-2026-96400No exploit | Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINSgitea · gitea · CWE-918 | Medium4.3 | — | 0.2% | 4 days ago |
39Monitor | CVE-2026-94205No exploit | Gitea fork workflow approval bypass through maintainer-triggered eventsgitea · gitea · CWE-441 | Critical9.8 | — | 0.3% | 4 days ago |
32Monitor | CVE-2026-89430No exploit | Gitea push mirror SSRF and forced writes to internal Git hostsgitea · gitea · CWE-367 | High8.1 | — | 0.2% | 4 days ago |
28Monitor | CVE-2026-79960No exploit | Gitea deploy key pushes acting as the repository ownergitea · gitea · CWE-863 | High7.1 | — | 0.2% | 4 days ago |
30Monitor | CVE-2026-70357No exploit | Gitea repository migration SSRF through DNS rebindinggitea · gitea · CWE-918 | High7.5 | — | 0.3% | 4 days ago |
30Monitor | CVE-2026-104636No exploit | Gitea SSRF through Git HTTP redirects in mirrors and fetchesgitea · gitea · CWE-918 | High7.5 | — | 0.3% | 4 days ago |
35Monitor | CVE-2026-104632No exploit | Gitea fork workflow approval bypass through cancel and rerungitea · gitea · CWE-285 | High8.8 | — | 0.3% | 4 days ago |
35Monitor | CVE-2026-104626No exploit | Gitea fork workflow job revival through later approvalgitea · gitea · CWE-841 | High8.8 | — | 0.3% | 4 days ago |
30Monitor | CVE-2026-103670No exploit | Gitea trusted workflow cancellation by unapproved fork runsgitea · gitea · CWE-667 | High7.5 | — | 0.2% | 4 days ago |
32Monitor | CVE-2026-103504No exploit | Gitea API team demotion not applied to unit permissionsgitea · gitea · CWE-272 | High8.1 | — | 0.3% | 4 days ago |
17Monitor | CVE-2026-101029No exploit | Gitea migration and pull mirror SSRF through multi-answer DNSgitea · gitea · CWE-209 | Medium4.3 | — | 0.2% | 4 days ago |
30Monitor | CVE-2026-101027No exploit | Gitea migration SSRF through ALLOWED_DOMAINS address check bypassgitea · gitea · CWE-346 | High7.7 | — | 0.2% | 4 days ago |
- CVE-2026-9762617Monitor
Gitea profile feed disclosure bypassing user visibility
MediumCVSS 4.3No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-9720819Monitor
Gitea push mirror API bypass of DISABLE_NEW_PUSH policy
MediumCVSS 4.9No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-9659424Monitor
Gitea repository media API stored XSS
MediumCVSS 6.1No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-8918221Monitor
Gitea push-to-create bypass of FORCE_PRIVATE policy
MediumCVSS 5.4No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-8668428Monitor
Gitea push mirror local path check uses the repository owner
HighCVSS 7.1No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-10526817Monitor
Gitea issue attachment API allows changing comment attachments
MediumCVSS 4.3No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-10526732Monitor
Gitea tag delete route deletes releases without release permission
HighCVSS 8.1No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-10463326Monitor
Gitea migration memory exhaustion from zero page size
MediumCVSS 6.5No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-10102336Monitor
Gitea OAuth2 refresh token grant accepts access tokens
CriticalCVSS 9.1No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-9658917Monitor
Gitea private repository access retained after rejected transfer
MediumCVSS 4.3No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-9658030Monitor
Gitea Actions memory exhaustion through large static matrices
HighCVSS 7.5No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-9640017Monitor
Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS
MediumCVSS 4.3No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-9420539Monitor
Gitea fork workflow approval bypass through maintainer-triggered events
CriticalCVSS 9.8No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-8943032Monitor
Gitea push mirror SSRF and forced writes to internal Git hosts
HighCVSS 8.1No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-7996028Monitor
Gitea deploy key pushes acting as the repository owner
HighCVSS 7.1No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-7035730Monitor
Gitea repository migration SSRF through DNS rebinding
HighCVSS 7.5No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-10463630Monitor
Gitea SSRF through Git HTTP redirects in mirrors and fetches
HighCVSS 7.5No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-10463235Monitor
Gitea fork workflow approval bypass through cancel and rerun
HighCVSS 8.8No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-10462635Monitor
Gitea fork workflow job revival through later approval
HighCVSS 8.8No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-10367030Monitor
Gitea trusted workflow cancellation by unapproved fork runs
HighCVSS 7.5No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-10350432Monitor
Gitea API team demotion not applied to unit permissions
HighCVSS 8.1No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-10102917Monitor
Gitea migration and pull mirror SSRF through multi-answer DNS
MediumCVSS 4.3No exploitEPSS 0%gitea · gitea4 days ago
- CVE-2026-10102730Monitor
Gitea migration SSRF through ALLOWED_DOMAINS address check bypass
HighCVSS 7.7No exploitEPSS 0%gitea · gitea4 days ago