{"api_version":"v1","generated_at":"2026-10-08T14:05:00+00:00","product":{"cve_count":44,"evidence_gap_note":"This CVE identity is linked to an existing Lifecycle product history.","id":"security:cve-gitea-gitea-bc3d6b900aad","lifecycle_state":"covered","linked_lifecycle_url":"https://lifecycle.blacktree.nl/targets/gitea","name":"Gitea","next_cursor":null,"observations":[{"affected":"Gitea: \u2264 28.0.0","affected_versions_present":true,"cve_id":"CVE-2026-97626","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-97626","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:01:58.662Z","patch_url":"","primary_source":"","published":"2026-10-06T21:36:48.056Z"},{"affected":"Gitea: \u2264 28.0.0","affected_versions_present":true,"cve_id":"CVE-2026-96594","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-96594","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T15:04:26.695Z","patch_url":"","primary_source":"","published":"2026-10-06T21:36:38.491Z"},{"affected":"Gitea: 1.27.0 \u2264 28.0.0","affected_versions_present":true,"cve_id":"CVE-2026-89182","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-89182","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T11:34:42.708Z","patch_url":"","primary_source":"","published":"2026-10-06T21:36:01.187Z"},{"affected":"Gitea: \u2264 28.0.0","affected_versions_present":true,"cve_id":"CVE-2026-105268","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-105268","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T16:12:20.545Z","patch_url":"","primary_source":"","published":"2026-10-06T21:35:40.926Z"},{"affected":"Gitea: \u2264 28.0.0","affected_versions_present":true,"cve_id":"CVE-2026-105267","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-105267","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:02:51.066Z","patch_url":"","primary_source":"","published":"2026-10-06T21:35:35.508Z"},{"affected":"Gitea: \u2264 28.0.0","affected_versions_present":true,"cve_id":"CVE-2026-104633","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-104633","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T15:53:48.550Z","patch_url":"","primary_source":"","published":"2026-10-06T21:35:26.516Z"},{"affected":"Gitea: \u2264 28.0.0","affected_versions_present":true,"cve_id":"CVE-2026-101023","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-101023","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:04:04.946Z","patch_url":"","primary_source":"","published":"2026-10-06T21:34:53.642Z"},{"affected":"Gitea: \u2264 28.0.0","affected_versions_present":true,"cve_id":"CVE-2026-97208","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-97208","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:05:11.889Z","patch_url":"","primary_source":"","published":"2026-10-06T21:17:46.887Z"},{"affected":"Gitea: 1.18.0 \u2264 28.0.0","affected_versions_present":true,"cve_id":"CVE-2026-86684","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86684","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:06:11.954Z","patch_url":"","primary_source":"","published":"2026-10-06T21:17:09.942Z"},{"affected":"Gitea: 1.16.0 \u2264 1.27.1","affected_versions_present":true,"cve_id":"CVE-2026-73278","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73278","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:00:46.107Z","patch_url":"","primary_source":"","published":"2026-10-06T19:33:54.375Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-96589","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-96589","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T14:30:41.814Z","patch_url":"","primary_source":"","published":"2026-10-06T19:25:38.737Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-96580","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-96580","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:09:31.410Z","patch_url":"","primary_source":"","published":"2026-10-06T19:25:33.619Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-96404","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-96404","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T14:26:56.170Z","patch_url":"","primary_source":"","published":"2026-10-06T19:25:28.457Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-96400","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-96400","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T11:35:27.280Z","patch_url":"","primary_source":"","published":"2026-10-06T19:25:23.261Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-96399","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-96399","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:10:45.979Z","patch_url":"","primary_source":"","published":"2026-10-06T19:25:18.075Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-95112","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-95112","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-06T19:25:12.973Z","patch_url":"","primary_source":"","published":"2026-10-06T19:25:12.973Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-94205","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-94205","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:11:55.392Z","patch_url":"","primary_source":"","published":"2026-10-06T19:25:04.327Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-79960","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-79960","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T14:21:39.950Z","patch_url":"","primary_source":"","published":"2026-10-06T19:24:55.742Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-70357","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-70357","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:12:56.425Z","patch_url":"","primary_source":"","published":"2026-10-06T19:24:50.540Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-104636","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-104636","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:13:59.342Z","patch_url":"","primary_source":"","published":"2026-10-06T19:24:45.427Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-103504","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-103504","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:15:03.095Z","patch_url":"","primary_source":"","published":"2026-10-06T19:24:26.369Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-95106","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-95106","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:08:30.652Z","patch_url":"","primary_source":"","published":"2026-10-06T19:23:57.452Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-89430","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-89430","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:16:04.169Z","patch_url":"","primary_source":"","published":"2026-10-06T19:23:52.198Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-103670","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-103670","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T15:58:09.298Z","patch_url":"","primary_source":"","published":"2026-10-06T19:23:40.050Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-103667","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-103667","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:17:12.875Z","patch_url":"","primary_source":"","published":"2026-10-06T19:23:34.873Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-101029","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-101029","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:18:20.660Z","patch_url":"","primary_source":"","published":"2026-10-06T19:23:26.328Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-101027","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-101027","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T15:54:52.293Z","patch_url":"","primary_source":"","published":"2026-10-06T19:23:20.387Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-104626","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-104626","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:19:46.339Z","patch_url":"","primary_source":"","published":"2026-10-06T19:23:03.330Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-103059","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-103059","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T14:17:20.596Z","patch_url":"","primary_source":"","published":"2026-10-06T19:22:57.192Z"},{"affected":"Gitea: \u2264 1.27.3","affected_versions_present":true,"cve_id":"CVE-2026-104632","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-104632","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-07T20:21:23.687Z","patch_url":"","primary_source":"","published":"2026-10-06T19:22:04.308Z"},{"affected":"Gitea: 1.17 < 1.27.1","affected_versions_present":true,"cve_id":"CVE-2026-60004","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-60004","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-08T18:03:21.873Z","patch_url":"https://github.com/0xBlackash/CVE-2026-60004","primary_source":"","published":"2026-08-26T19:45:00.000Z"},{"affected":"Gitea: \u2264 1.26.4","affected_versions_present":true,"cve_id":"CVE-2026-34966","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34966","fixed":"Gitea: 1.27.0","last_modified":"2026-08-14T16:49:46.740Z","patch_url":"https://github.com/go-gitea/gitea","primary_source":"","published":"2026-08-05T20:28:57.744Z"},{"affected":"< 1.25.2","affected_versions_present":true,"cve_id":"CVE-2025-69413","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-69413","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-05T19:56:03.799Z","patch_url":"https://github.com/go-gitea/gitea/pull/36002","primary_source":"","published":"2026-01-01T04:39:48.140Z"},{"affected":"1.20.0 < 1.20.1","affected_versions_present":true,"cve_id":"CVE-2025-68946","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68946","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-26T18:59:45.647Z","patch_url":"https://github.com/go-gitea/gitea/pull/25960","primary_source":"","published":"2025-12-26T04:14:03.775Z"},{"affected":"< 1.21.2","affected_versions_present":true,"cve_id":"CVE-2025-68945","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68945","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-26T18:59:29.985Z","patch_url":"https://github.com/go-gitea/gitea/pull/28423","primary_source":"","published":"2025-12-26T03:58:46.724Z"},{"affected":"< 1.22.2","affected_versions_present":true,"cve_id":"CVE-2025-68944","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68944","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-12-26T19:28:23.900Z","patch_url":"","primary_source":"","published":"2025-12-26T03:37:28.693Z"},{"affected":"< 1.21.8","affected_versions_present":true,"cve_id":"CVE-2025-68943","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68943","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-12-26T19:28:57.206Z","patch_url":"","primary_source":"","published":"2025-12-26T03:19:45.242Z"},{"affected":"< 1.22.2","affected_versions_present":true,"cve_id":"CVE-2025-68942","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68942","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-26T19:30:04.360Z","patch_url":"https://github.com/go-gitea/gitea/pull/31966","primary_source":"","published":"2025-12-26T02:50:35.144Z"},{"affected":"< 1.22.3","affected_versions_present":true,"cve_id":"CVE-2025-68941","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68941","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-26T19:31:33.303Z","patch_url":"https://github.com/go-gitea/gitea/pull/32218","primary_source":"","published":"2025-12-26T02:31:59.031Z"},{"affected":"< 1.22.5","affected_versions_present":true,"cve_id":"CVE-2025-68940","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68940","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-26T18:57:56.965Z","patch_url":"https://github.com/go-gitea/gitea/pull/32654","primary_source":"","published":"2025-12-26T02:14:52.076Z"},{"affected":"< 1.23.0","affected_versions_present":true,"cve_id":"CVE-2025-68939","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68939","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-26T18:57:27.065Z","patch_url":"https://github.com/go-gitea/gitea/pull/32151","primary_source":"","published":"2025-12-26T02:03:59.691Z"},{"affected":"< 1.25.2","affected_versions_present":true,"cve_id":"CVE-2025-68938","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68938","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-26T18:53:35.494Z","patch_url":"https://github.com/go-gitea/gitea/pull/36002/commits/d4262131b39899d9e9ee5caa2635c810d476e43f#diff-8962bac89952027d50fa51f31f59d65bedb4c02bde0265eced5cf256cbed306d","primary_source":"","published":"2025-12-26T01:19:10.609Z"},{"affected":"1.7.0 and earlier [fixed: 1.7.1 and later]","affected_versions_present":true,"cve_id":"CVE-2019-1010261","cve_url":"https://cve.blacktree.nl/cve/CVE-2019-1010261","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-05T03:07:18.495Z","patch_url":"https://github.com/go-gitea/gitea/pull/5905","primary_source":"","published":"2019-07-18T16:30:02.000Z"},{"affected":"1.7.2, 1.7.3","affected_versions_present":true,"cve_id":"CVE-2019-1010314","cve_url":"https://cve.blacktree.nl/cve/CVE-2019-1010314","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-05T03:07:18.527Z","patch_url":"","primary_source":"","published":"2019-07-11T19:33:46.000Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"Gitea"}}
