[Bug 294752] update www/gitea to 1.26 to address security issues
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 294752] update www/gitea to 1.26 to address security issues"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 294752] update www/gitea to 1.26 to address security issues"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 294752] update www/gitea to 1.26 to address security issues"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 294752] update www/gitea to 1.26 to address security issues"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 294752] update www/gitea to 1.26 to address security issues"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 294752] update www/gitea to 1.26 to address security issues"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 294752] update www/gitea to 1.26 to address security issues"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 294752] update www/gitea to 1.26 to address security issues"
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Fri, 24 Apr 2026 11:32:38 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=294752
Bug ID: 294752
Summary: update www/gitea to 1.26 to address security issues
Product: Ports & Packages
Version: Latest
Hardware: Any
OS: Any
Status: New
Severity: Affects Many People
Priority: ---
Component: Individual Port(s)
Assignee: ports-bugs@FreeBSD.org
Reporter: filis@FreeBSD.org
CC: ports@foss-daily.org
CC: ports@foss-daily.org
Flags: maintainer-feedback?(ports@foss-daily.org)
according to https://blog.gitea.com/release-of-1.26.0/
This release addresses several important security vulnerabilities:
CVE-2026-28737: Stored XSS in the Gitea 3D File Viewer via the glTF
extensionsRequired field. Fixed by #37233. Thanks to @yonatan-pl for reporting
the issue, and to @silverwind and @wxiaoguang for the patch.
CVE-2026-22555: Missing CanCreateOrgRepo check in the API fork flow allowed
exfiltration of organization secrets. Fixed by #36950. Thanks to @andrejtomci
for reporting the issue, and to @lunny for the patch.
CVE-2026-27780: Branch protection bypass caused by silent truncation in
bufio.Scanner during pre-receive hook processing. Fixed by #36963. Thanks to
@yonatan-pl for reporting the issue, and to @lunny for the patch.
--
You are receiving this mail because:
You are the assignee for the bug.