References https://github.com/plbplbp/loudong001/blob/main/Git/Git%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E(CVE-2024-32002).md https://www.cnblogs.com/Hi-blog/p/18224773/git_rce_CVE-2024-32002 https://www.secrss.com/articles/66299 https://blog.csdn.net/qq_64177395/article/details/143021761 https://www.anquanke.com/post/id/146909 https://cloud.tencent.com/developer/article/2424072 https://rivers.chaitin.cn/blog/cq94auh0lnechd242t30 https://www.ithome.com.tw/news/163000 https://cloud.tencent.com/developer/article/2419683 https://github.blog/security/securing-the-git-push-pipeline-responding-to-a-critical-remote-code-execution-vulnerability/ https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
Related VulnerabilitiesPoCCVE-2026-19478: GitLab CE/EE - GraphQL @gl_introduced Arbitrary Method InvocationPoCCVE-2026-20896: Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Authentication BypassPoCibm-websphere-ssrf: IBM WebSphere HCL Digital Experience - Server-Side Request ForgeryPoCCVE-2026-59774: Gitea 1.22.1-1.27.0 - Unauthenticated Arbitrary File ReadPoCCVE-2026-60004: Gitea <= 1.27.0 - Pre-Auth Remote Code ExecutionPoCCVE-2020-36884: BrightSign Digital Signage 8.2.26 - Server-Side Request ForgeryPoCCVE-2026-27771: Gitea Container Registry - Unauthorized Private Image AccessGitea /v2/_catalog 未授权访问漏洞(CVE-2026-27771)gitea-forgejo存在身份认证绕过(CVE-2026-27771)PoCgitea-userenum: Gitea - User EnumerationGitea用户信息泄露PoCCVE-2021-45328: Gitea < 1.4.3 - Open RedirectPoCgitea-open-redirect-bypass: Gitea < 1.21.0 - Open Redirect