CVE-2026-13540Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in GitBucket up to 4.46.1. This affects the function Git.cloneRepository.setURI of the file src/main/scala/gitbucket/core/service/RepositoryCreationService.scala. Performing a manipulation of the argument url results in server-side request forgery. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The patch is named 487a9b980f56aa73b6a044b1e86a92eed5043215. To fix this issue, it is recommended to deploy a patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-29: 3Technical Details · 2026-06-29: 206-29
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13540 A security flaw has been discovered in GitBucket up to 4.46.1. This affects the function Git.cloneRepository.setURI of the file src/main/scala/gitbucket/core/service/… https://www.cve.org/CVERecord?id=CVE-2026-13540 ----- Traducción: CVE-2026-13540 Se … http://infoflow.cloud`

    Post summary

    A new GitBucket vulnerability (CVE-2026-13540) affecting the Git.cloneRepository.setURI function up to version 4.46.1 has been announced; no PoC, exploit, or patch information is provided.

    0001033
    89 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-13540 Server-Side Request Forgery in GitBucket Up To 4.46.1 via... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13540 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The text announces a Server‑Side Request Forgery vulnerability in GitBucket versions up to 4.46.1 and directs readers to a vulnerability details page and scanning alert resource.

    00010124
    4.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-13540 A security flaw has been discovered in GitBucket up to 4.46.1. This affects the function Git.cloneRepository.setURI of the file src/main/scala/gitbucket/core/service/… https://www.cve.org/CVERecord?id=CVE-2026-13540

    Post summary

    The text announces the discovery of CVE‑2026‑13540 in GitBucket affecting the Git.cloneRepository.setURI function, but provides only basic technical details without mentioning exploitation, patches, or a PoC.

    00000739
    57.7K followersView on X

Explore more