Логотип exploitDog
bind:CVE-2026-20736
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-20736

Количество 3

Количество 3

nvd логотип

CVE-2026-20736

17 дней назад

Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a different repository they can access.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-20736

17 дней назад

Gitea does not properly verify repository context when deleting attach ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-hgr3-x44x-33hx

17 дней назад

Gitea has improper access control for uploaded attachments

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-20736

Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a different repository they can access.

CVSS3: 7.5
0%
Низкий
17 дней назад
debian логотип
CVE-2026-20736

Gitea does not properly verify repository context when deleting attach ...

CVSS3: 7.5
0%
Низкий
17 дней назад
github логотип
GHSA-hgr3-x44x-33hx

Gitea has improper access control for uploaded attachments

0%
Низкий
17 дней назад

Уязвимостей на страницу