Gitea
by Go Gitea
Source repositories
CVEs (146)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-58510 | Med | 0.28 | 4.3 | 0.00 | Aug 13, 2026 | GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private | ||
| CVE-2026-58431 | Med | 0.28 | 4.3 | 0.00 | Aug 13, 2026 | Public-only API token restriction is not enforced on team API routes | ||
| CVE-2026-55986 | Med | 0.28 | 5.4 | 0.00 | Aug 13, 2026 | Email Management API Bypasses ManageCredentials Feature Restrictions | ||
| CVE-2026-50105 | Med | 0.28 | 4.3 | 0.00 | Aug 13, 2026 | RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) | ||
| CVE-2025-68946 | Med | 0.28 | 5.4 | 0.00 | Dec 26, 2025 | In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS. | ||
| CVE-2025-68942 | Med | 0.28 | 5.4 | 0.00 | Dec 26, 2025 | Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text. | ||
| CVE-2022-1928 | Med | 0.28 | 5.4 | 0.01 | May 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9. | ||
| CVE-2018-1000803 | Med | 0.28 | 5.3 | 0.01 | Oct 8, 2018 | Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appear to be exploitable via Watch a repository to receive email notifications. Emails received contain the other recipients even if… | ||
| CVE-2026-58507 | Med | 0.27 | 5.3 | 0.00 | Aug 13, 2026 | Private Repository Existence Disclosure via go-get Meta Endpoint | ||
| CVE-2025-69413 | Med | 0.27 | 5.3 | 0.00 | Jan 1, 2026 | In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists. | ||
| CVE-2025-68943 | Med | 0.27 | 5.3 | 0.00 | Dec 26, 2025 | Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order. | ||
| CVE-2026-59766 | med | 0.26 | — | — | Jul 21, 2026 | ## Summary CVE-2026-20800 fixed private-info leakage to revoked users only for the notification endpoint. Two sibling endpoints that return data keyed on the caller's own relationship still do not re-check repo access at output time: - `GET /api/v1/user/starred` —… | ||
| CVE-2025-68944 | Med | 0.26 | 5.0 | 0.00 | Dec 26, 2025 | Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries. | ||
| CVE-2026-58429 | Med | 0.25 | 4.9 | 0.00 | Aug 13, 2026 | Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints | ||
| CVE-2025-68941 | Med | 0.25 | 4.9 | 0.00 | Dec 26, 2025 | Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources. | ||
| CVE-2026-52807 | Med | 0.24 | — | 0.00 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, in new_form.tmpl, milestone names are rendered with Go's default auto-escaping ({{.Name}}), which converts < to < etc. This prevents direct HTML injection. However, when the browser renders the DOM, the text… | ||
| CVE-2023-3515 | Med | 0.22 | 4.4 | 0.00 | Jul 5, 2023 | Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4. | ||
| CVE-2026-59763 | Med | 0.21 | 4.3 | 0.00 | Aug 13, 2026 | Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads | ||
| CVE-2026-58444 | Med | 0.21 | 4.3 | 0.00 | Aug 13, 2026 | Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents | ||
| CVE-2026-58425 | Med | 0.21 | 4.3 | 0.00 | Aug 13, 2026 | OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) |
- risk 0.28cvss 4.3epss 0.00
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
- risk 0.28cvss 4.3epss 0.00
Public-only API token restriction is not enforced on team API routes
- risk 0.28cvss 5.4epss 0.00
Email Management API Bypasses ManageCredentials Feature Restrictions
- risk 0.28cvss 4.3epss 0.00
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
- risk 0.28cvss 5.4epss 0.00
In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.
- risk 0.28cvss 5.4epss 0.00
Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.
- risk 0.28cvss 5.3epss 0.01
Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appear to be exploitable via Watch a repository to receive email notifications. Emails received contain the other recipients even if…
- risk 0.27cvss 5.3epss 0.00
Private Repository Existence Disclosure via go-get Meta Endpoint
- risk 0.27cvss 5.3epss 0.00
In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.
- risk 0.27cvss 5.3epss 0.00
Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.
- risk 0.26cvss —epss —
## Summary CVE-2026-20800 fixed private-info leakage to revoked users only for the notification endpoint. Two sibling endpoints that return data keyed on the caller's own relationship still do not re-check repo access at output time: - `GET /api/v1/user/starred` —…
- risk 0.26cvss 5.0epss 0.00
Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.
- risk 0.25cvss 4.9epss 0.00
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
- risk 0.25cvss 4.9epss 0.00
Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.
- risk 0.24cvss —epss 0.00
Gogs is an open source self-hosted Git service. Prior to 0.14.3, in new_form.tmpl, milestone names are rendered with Go's default auto-escaping ({{.Name}}), which converts < to < etc. This prevents direct HTML injection. However, when the browser renders the DOM, the text…
- risk 0.22cvss 4.4epss 0.00
Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4.
- risk 0.21cvss 4.3epss 0.00
Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
- risk 0.21cvss 4.3epss 0.00
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
- risk 0.21cvss 4.3epss 0.00
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
Page 5 of 8