Known vulnerabilities in Gitea 1.27.2

Software: Gitea
Version: 1.27.2
Software CPE: cpe:2.3:a:the_gitea_authors:gitea:*:*:*:*:*:*:*:*
Total vulnerabilities: 23
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.7

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Gitea version 1.27.2 Gitea 1.27.2 is affected by 23 vulnerabilities: 4 medium, 19 low Critical High Medium Low

Vulnerabilities (23)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU146370 - Incorrect Authorization
CVE-2026-70396
CWE-863 Low
No
No
1.27.3 31.08.2026 SB2026083147
#VU146369 - Incorrect Authorization
CVE-2026-70400
CWE-863 Low
No
No
1.27.3 31.08.2026 SB2026083147
#VU146368 - Incorrect Permission Assignment for Critical Resource
CVE-2026-70402
CWE-732 Low
No
No
1.27.3 31.08.2026 SB2026083147
#VU146367 - Improper Authorization
CVE-2026-70407
CWE-285 Low
No
No
1.27.3 31.08.2026 SB2026083147
#VU146365 - Improper Access Control
CVE-2026-71301
CWE-284 Low
No
No
1.27.3 31.08.2026 SB2026083147
#VU146364 - Observable discrepancy
CVE-2026-73504
CWE-203 Medium
No
No
1.27.3 31.08.2026 SB2026083147
#VU146363 - Incorrect Authorization
CVE-2026-73126
CWE-863 Low
No
No
1.27.3 31.08.2026 SB2026083147
#VU146362 - Resource exhaustion
CVE-2026-73130
CWE-400 Low
No
No
1.27.3 31.08.2026 SB2026083147
#VU146360 - Allocation of Resources Without Limits or Throttling
CVE-2026-73273
CWE-770 Low
No
No
1.27.3 31.08.2026 SB2026083147
#VU146359 - Incorrect Authorization
CVE-2026-60010
CWE-863 Medium
No
No
1.27.3 31.08.2026 SB2026083147
#VU146358 - Resource exhaustion
CVE-2026-60018
CWE-400 Low
No
No
1.27.3 31.08.2026 SB2026083147
#VU146357 - Resource exhaustion
CVE-2026-60021
CWE-400 Low
No
No
1.27.3 31.08.2026 SB2026083147
#VU146356 - Resource exhaustion
CVE-2026-62925
CWE-400 Low
No
No
1.27.3 31.08.2026 SB2026083147
#VU146355 - Resource exhaustion
CVE-2026-63021
CWE-400 Low
No
No
1.27.3 31.08.2026 SB2026083147
#VU146354 - Improper Handling of Insufficient Permissions or Privileges
CVE-2026-63792
CWE-280 Low
No
No
1.27.3 31.08.2026 SB2026083147
#VU146353 - Improper Access Control
CVE-2026-66849
CWE-284 Low
No
No
1.27.3 31.08.2026 SB2026083147
#VU146352 - Incorrect Authorization
CVE-2026-66853
CWE-863 Low
No
No
1.27.3 31.08.2026 SB2026083147
#VU146351 - Reliance on Untrusted Inputs in a Security Decision
CVE-2026-66874
CWE-807 Low
No
No
1.27.3 31.08.2026 SB2026083147
#VU146350 - Improper Access Control
CVE-2026-66877
CWE-284 Medium
No
No
1.27.3 31.08.2026 SB2026083147
#VU146346 - Authorization Bypass Through User-Controlled Key
CVE-2026-78433
CWE-639 Medium
No
No
1.27.3 31.08.2026 SB2026083147


Showing elements 1 - 20 out of 23