peter bassill · operator
$ cve CVE-2018-18926 JSON

CVE-2018-18926

9.8
CRITICAL · CVSS 3.0 · EPSS 3% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to session ID handling in the go-macaron/session code for Macaron.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.04% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-384
On CISA KEVno
Public exploitnone known
Published2018-11-04
Last modified2026-06-17

Affected (1)

VendorProduct
giteagitea

References

→ the Explorer  ·  watch your stack  ·  NVD