CVE-2026-54481

Published: Ago 13, 2026 Last Modified: Ago 13, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)

295

Improper Certificate Validation

Draft
Common Consequences
Security Scopes Affected:
Integrity Authentication
Potential Impacts:
Bypass Protection Mechanism Gain Privileges Or Assume Identity
Applicable Platforms
Technologies: Not Technology-Specific, Web Based, Mobile
View CWE Details
https://blog.gitea.com/gitea-1.27.0-is-released/
https://github.com/go-gitea/gitea/releases/tag/v1.27.0
https://github.com/go-gitea/gitea/security/advisories/GHSA-94v3-77j7-vm48