CVE-2026-73504

critical

Description

Gitea reports: This release contains fixes for 26 security issues, hardens issue searching that an unfiltered query no longer enumerates every public repository into the indexer filter and removes unsafe code from the internal private endpoints. Please upgrade as soon as possible.

Details

Source: Mitre, NVD

Published: 2026-09-13

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical