Gitea
by Go Gitea
Source repositories
CVEs (147)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-28744 | Hig | 0.46 | 8.1 | 0.00 | Jul 3, 2026 | Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks. | ||
| CVE-2026-28699 | Hig | 0.46 | 8.1 | 0.01 | Jul 3, 2026 | Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication. | ||
| CVE-2026-22555 | Hig | 0.46 | 8.1 | 0.00 | Jul 3, 2026 | Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets. | ||
| CVE-2025-68939 | Hig | 0.46 | 8.2 | 0.00 | Dec 26, 2025 | Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API. | ||
| CVE-2026-58314 | Hig | 0.43 | 7.7 | 0.00 | Aug 13, 2026 | Two SSRF findings in Gitea 1.26.2 | ||
| CVE-2026-58423 | Hig | 0.43 | 7.7 | 0.01 | Jul 3, 2026 | LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories | ||
| CVE-2026-58442 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Repository migration SSRF via multi-answer DNS allow-list bypass | ||
| CVE-2026-58436 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests | ||
| CVE-2026-58434 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | Private Repository Metadata Remains Accessible After Access Revocation | ||
| CVE-2026-58427 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 | ||
| CVE-2026-58417 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | REST API exposes organization membership of private organizations to public | ||
| CVE-2026-42931 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint | ||
| CVE-2026-34966 | Hig | 0.42 | 7.6 | 0.00 | Aug 5, 2026 | Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext.… | ||
| CVE-2026-58421 | Hig | 0.42 | 7.5 | 0.01 | Jul 3, 2026 | Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service | ||
| CVE-2026-58419 | Hig | 0.42 | 7.5 | 0.01 | Jul 3, 2026 | Notification API leaks private issue metadata after access revocation | ||
| CVE-2026-27779 | Hig | 0.42 | 7.5 | 0.01 | Jul 3, 2026 | Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation. | ||
| CVE-2026-27660 | Hig | 0.42 | 7.5 | 0.00 | Jul 3, 2026 | Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission. | ||
| CVE-2026-27657 | Hig | 0.42 | 7.5 | 0.00 | Jul 3, 2026 | Gitea versions before 1.25.5 allow a user to change another user's primary email address. | ||
| CVE-2026-26307 | Hig | 0.42 | 7.5 | 0.01 | Jul 3, 2026 | Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources. | ||
| CVE-2026-25712 | Hig | 0.42 | 7.5 | 0.00 | Jul 3, 2026 | Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations. |
- risk 0.46cvss 8.1epss 0.00
Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.
- risk 0.46cvss 8.1epss 0.01
Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.
- risk 0.46cvss 8.1epss 0.00
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.
- risk 0.46cvss 8.2epss 0.00
Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.
- risk 0.43cvss 7.7epss 0.00
Two SSRF findings in Gitea 1.26.2
- risk 0.43cvss 7.7epss 0.01
LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
- risk 0.42cvss 6.5epss 0.00
Repository migration SSRF via multi-answer DNS allow-list bypass
- risk 0.42cvss 7.5epss 0.00
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
- risk 0.42cvss 7.5epss 0.00
Private Repository Metadata Remains Accessible After Access Revocation
- risk 0.42cvss 7.5epss 0.00
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
- risk 0.42cvss 7.5epss 0.00
REST API exposes organization membership of private organizations to public
- risk 0.42cvss 6.5epss 0.00
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
- risk 0.42cvss 7.6epss 0.00
Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext.…
- risk 0.42cvss 7.5epss 0.01
Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
- risk 0.42cvss 7.5epss 0.01
Notification API leaks private issue metadata after access revocation
- risk 0.42cvss 7.5epss 0.01
Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
- risk 0.42cvss 7.5epss 0.00
Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.
- risk 0.42cvss 7.5epss 0.00
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
- risk 0.42cvss 7.5epss 0.01
Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.
- risk 0.42cvss 7.5epss 0.00
Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.
Page 3 of 8