[Bug 294752] update www/gitea to 1.26 to address security issues

From: <bugzilla-noreply_at_freebsd.org>
Date: Fri, 24 Apr 2026 11:32:38 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=294752

            Bug ID: 294752
           Summary: update www/gitea to 1.26 to address security issues
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Many People
          Priority: ---
         Component: Individual Port(s)
          Assignee: ports-bugs@FreeBSD.org
          Reporter: filis@FreeBSD.org
                CC: ports@foss-daily.org
                CC: ports@foss-daily.org
             Flags: maintainer-feedback?(ports@foss-daily.org)

according to https://blog.gitea.com/release-of-1.26.0/ 

This release addresses several important security vulnerabilities:

    CVE-2026-28737: Stored XSS in the Gitea 3D File Viewer via the glTF
extensionsRequired field. Fixed by #37233. Thanks to @yonatan-pl for reporting
the issue, and to @silverwind and @wxiaoguang for the patch.

    CVE-2026-22555: Missing CanCreateOrgRepo check in the API fork flow allowed
exfiltration of organization secrets. Fixed by #36950. Thanks to @andrejtomci
for reporting the issue, and to @lunny for the patch.

    CVE-2026-27780: Branch protection bypass caused by silent truncation in
bufio.Scanner during pre-receive hook processing. Fixed by #36963. Thanks to
@yonatan-pl for reporting the issue, and to @lunny for the patch.

-- 
You are receiving this mail because:
You are the assignee for the bug.