Gitea
by Go Gitea
Source repositories
CVEs (147)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-60004 | Cri | 0.71 | 9.8 | 0.24 | KEV | Aug 26, 2026 | Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. | |
| CVE-2019-11229 | Hig | 0.65 | 8.8 | 0.55 | Apr 15, 2019 | models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution. | ||
| CVE-2021-45331 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2022 | An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once. | ||
| CVE-2021-45330 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2022 | An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse. | ||
| CVE-2020-28991 | Cri | 0.64 | 9.8 | 0.02 | Nov 24, 2020 | Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. | ||
| CVE-2019-11576 | Cri | 0.64 | 9.8 | 0.02 | Apr 28, 2019 | Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password. | ||
| CVE-2025-68937 | Cri | 0.62 | — | 0.01 | Dec 26, 2025 | Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositories. This is also fixed for 11 LTS in 11.0.7 and later. | ||
| CVE-2024-6886 | Cri | 0.61 | — | 0.33 | Aug 6, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0. | ||
| CVE-2026-58508 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2026 | Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | ||
| CVE-2026-58443 | Cri | 0.59 | 9.1 | 0.01 | Aug 13, 2026 | Public-only repository tokens can update private PR head branches | ||
| CVE-2026-58433 | Cri | 0.59 | 9.1 | 0.01 | Aug 13, 2026 | Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting | ||
| CVE-2026-55982 | Cri | 0.59 | 9.1 | 0.01 | Aug 13, 2026 | OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes | ||
| CVE-2026-56654 | Cri | 0.57 | 9.8 | 0.01 | Aug 13, 2026 | Privilege Escalation via Access Token Scope Escalation in API | ||
| CVE-2026-58422 | Cri | 0.57 | 9.8 | 0.01 | Jul 3, 2026 | Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts | ||
| CVE-2026-28737 | Hig | 0.57 | 8.7 | 0.00 | Jul 3, 2026 | Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer. | ||
| CVE-2026-27780 | Cri | 0.57 | 9.8 | 0.01 | Jul 3, 2026 | Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks. | ||
| CVE-2026-26292 | Cri | 0.57 | 9.8 | 0.01 | Jul 3, 2026 | Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests. | ||
| CVE-2026-20896 | Cri | 0.57 | 9.8 | 0.03 | Jul 3, 2026 | Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled. | ||
| CVE-2022-42968 | Cri | 0.57 | 9.8 | 0.01 | Oct 16, 2022 | Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. | ||
| CVE-2021-45327 | Cri | 0.57 | 9.8 | 0.02 | Feb 8, 2022 | Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code. |
- risk 0.71cvss 9.8epss 0.24
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
- risk 0.65cvss 8.8epss 0.55
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.
- risk 0.64cvss 9.8epss 0.01
An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.
- risk 0.64cvss 9.8epss 0.01
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.
- risk 0.64cvss 9.8epss 0.02
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go.
- risk 0.64cvss 9.8epss 0.02
Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password.
- risk 0.62cvss —epss 0.01
Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositories. This is also fixed for 11 LTS in 11.0.7 and later.
- risk 0.61cvss —epss 0.33
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.
- risk 0.59cvss 9.1epss 0.00
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
- risk 0.59cvss 9.1epss 0.01
Public-only repository tokens can update private PR head branches
- risk 0.59cvss 9.1epss 0.01
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
- risk 0.59cvss 9.1epss 0.01
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
- risk 0.57cvss 9.8epss 0.01
Privilege Escalation via Access Token Scope Escalation in API
- risk 0.57cvss 9.8epss 0.01
Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
- risk 0.57cvss 8.7epss 0.00
Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer.
- risk 0.57cvss 9.8epss 0.01
Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.
- risk 0.57cvss 9.8epss 0.01
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
- risk 0.57cvss 9.8epss 0.03
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
- risk 0.57cvss 9.8epss 0.01
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.
- risk 0.57cvss 9.8epss 0.02
Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code.
Page 1 of 8