← לוח פגיעויות

CVE-2026-28744

גבוהה 8.1

תיאור (מקור, אנגלית)

Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.

מדדים

CVSS 3.1
8.1 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-16/8/2026
CWE
CWE-863

קישורים