CVE-2019-11576: Gitea
Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.
Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password.
Affected products
- Gitea Gitea: before 1.8.0 (fixed in 1.8.0)
Published 2019-04-28. Last modified 2026-06-17.