Gitea
by Go Gitea
Source repositories
CVEs (147)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-58418 | Med | 0.35 | 6.5 | 0.00 | Jul 3, 2026 | SSRF via HTTP Redirect in Repository Migration | ||
| CVE-2026-20904 | Med | 0.35 | 6.5 | 0.00 | Jan 22, 2026 | Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. | ||
| CVE-2026-20883 | Med | 0.35 | 6.5 | 0.00 | Jan 22, 2026 | Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. | ||
| CVE-2026-20800 | Med | 0.35 | 6.5 | 0.00 | Jan 22, 2026 | Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. | ||
| CVE-2022-38795 | Med | 0.35 | 6.5 | 0.01 | Aug 7, 2023 | In Gitea through 1.17.1, repo cloning can occur in the migration function. | ||
| CVE-2022-38183 | Med | 0.35 | 6.5 | 0.01 | Aug 12, 2022 | In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to… | ||
| CVE-2026-56755 | Med | 0.33 | 6.2 | 0.00 | Aug 13, 2026 | Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload | ||
| CVE-2021-45328 | Med | 0.33 | 6.1 | 0.01 | Feb 8, 2022 | Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs. | ||
| CVE-2019-1010314 | Med | 0.33 | 6.1 | 0.01 | Jul 11, 2019 | Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector is: victim must navigate to public and affected repo page. | ||
| CVE-2026-58432 | Med | 0.31 | 5.9 | 0.00 | Aug 13, 2026 | Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea | ||
| CVE-2026-57886 | Med | 0.31 | 5.9 | 0.00 | Aug 13, 2026 | Cross-repository issue/comment attachment re-linking can expose private attachment content | ||
| CVE-2025-68945 | Med | 0.31 | 5.8 | 0.00 | Dec 26, 2025 | In Gitea before 1.21.2, an anonymous user can visit a private user's project. | ||
| CVE-2026-58420 | Med | 0.29 | 4.4 | 0.00 | Aug 13, 2026 | Local File Inclusion via file:// URI in Migration Restore | ||
| CVE-2026-58510 | Med | 0.28 | 4.3 | 0.00 | Aug 13, 2026 | GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private | ||
| CVE-2026-58431 | Med | 0.28 | 4.3 | 0.00 | Aug 13, 2026 | Public-only API token restriction is not enforced on team API routes | ||
| CVE-2026-55986 | Med | 0.28 | 5.4 | 0.00 | Aug 13, 2026 | Email Management API Bypasses ManageCredentials Feature Restrictions | ||
| CVE-2026-50105 | Med | 0.28 | 4.3 | 0.00 | Aug 13, 2026 | RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) | ||
| CVE-2025-68946 | Med | 0.28 | 5.4 | 0.00 | Dec 26, 2025 | In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS. | ||
| CVE-2025-68942 | Med | 0.28 | 5.4 | 0.00 | Dec 26, 2025 | Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text. | ||
| CVE-2022-1928 | Med | 0.28 | 5.4 | 0.01 | May 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9. |
- risk 0.35cvss 6.5epss 0.00
SSRF via HTTP Redirect in Repository Migration
- risk 0.35cvss 6.5epss 0.00
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.
- risk 0.35cvss 6.5epss 0.00
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches.
- risk 0.35cvss 6.5epss 0.00
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications.
- risk 0.35cvss 6.5epss 0.01
In Gitea through 1.17.1, repo cloning can occur in the migration function.
- risk 0.35cvss 6.5epss 0.01
In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to…
- risk 0.33cvss 6.2epss 0.00
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
- risk 0.33cvss 6.1epss 0.01
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
- risk 0.33cvss 6.1epss 0.01
Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector is: victim must navigate to public and affected repo page.
- risk 0.31cvss 5.9epss 0.00
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
- risk 0.31cvss 5.9epss 0.00
Cross-repository issue/comment attachment re-linking can expose private attachment content
- risk 0.31cvss 5.8epss 0.00
In Gitea before 1.21.2, an anonymous user can visit a private user's project.
- risk 0.29cvss 4.4epss 0.00
Local File Inclusion via file:// URI in Migration Restore
- risk 0.28cvss 4.3epss 0.00
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
- risk 0.28cvss 4.3epss 0.00
Public-only API token restriction is not enforced on team API routes
- risk 0.28cvss 5.4epss 0.00
Email Management API Bypasses ManageCredentials Feature Restrictions
- risk 0.28cvss 4.3epss 0.00
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
- risk 0.28cvss 5.4epss 0.00
In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.
- risk 0.28cvss 5.4epss 0.00
Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.
Page 5 of 8