Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Gitea" — 19 resultados ✕ Limpiar búsqueda
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
G Alto vulnerabilidad
25/08/2026
[CVE-2026-60004] Vulnerabilidad explotada activamente en Gitea Gitea
CISA confirma explotación activa de una vulnerabilidad en Gitea Gitea. No se ha confirmado uso en campañas de ransomware conocidas. Fecha límite para aplicar parche según directiva CISA: 2026-08-28.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-34966] Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated…
Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints …
M Alto vulnerabilidad
03/07/2026
[CVE-2026-28744] Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer to…
Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27771] Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package s…
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27775] Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receiv…
Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-edit grant to be reused for other refs and escalate to full repository write access.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27779] Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting publ…
Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-28699] Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed…
Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/07/2026
[CVE-2026-28737] Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsReq…
Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-28740] Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source obj…
Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-26231] Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to …
Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-26307] Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searc…
Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27657] Gitea versions before 1.25.5 allow a user to change another user's primary email address.
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27660] Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the requ…
Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-22555] Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first…
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-24451] Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public t…
Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/07/2026
[CVE-2026-24690] Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull reque…
Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-25038] Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-25712] Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for…
Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-20779] Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a vali…
Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.