Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we
Go security advisories and CVEs.
Vulnerability disclosures, CVEs, security advisories, and patched releases.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests
Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
