VYPR

Gitea

by Go Gitea

Source repositories

CVEs (147)

  • CVE-2018-1000803MedOct 8, 2018
    risk 0.28cvss 5.3epss 0.01

    Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appear to be exploitable via Watch a repository to receive email notifications. Emails received contain the other recipients even if…

  • CVE-2026-58507MedAug 13, 2026
    risk 0.27cvss 5.3epss 0.00

    Private Repository Existence Disclosure via go-get Meta Endpoint

  • CVE-2026-28705MedJul 3, 2026
    risk 0.27cvss 5.3epss 0.00

    Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.

  • CVE-2026-25782MedJul 3, 2026
    risk 0.27cvss 5.3epss 0.00

    Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.

  • CVE-2026-20909MedJul 3, 2026
    risk 0.27cvss 5.3epss 0.00

    Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.

  • CVE-2025-69413MedJan 1, 2026
    risk 0.27cvss 5.3epss 0.00

    In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.

  • CVE-2025-68943MedDec 26, 2025
    risk 0.27cvss 5.3epss 0.00

    Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.

  • CVE-2026-59766medJul 21, 2026
    risk 0.26cvss —epss —

    ## Summary CVE-2026-20800 fixed private-info leakage to revoked users only for the notification endpoint. Two sibling endpoints that return data keyed on the caller's own relationship still do not re-check repo access at output time: - `GET /api/v1/user/starred` —…

  • CVE-2025-68944MedDec 26, 2025
    risk 0.26cvss 5.0epss 0.00

    Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.

  • CVE-2026-58429MedAug 13, 2026
    risk 0.25cvss 4.9epss 0.00

    Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

  • CVE-2025-68941MedDec 26, 2025
    risk 0.25cvss 4.9epss 0.00

    Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.

  • CVE-2026-52807MedJun 24, 2026
    risk 0.24cvss —epss 0.00

    Gogs is an open source self-hosted Git service. Prior to 0.14.3, in new_form.tmpl, milestone names are rendered with Go's default auto-escaping ({{.Name}}), which converts < to < etc. This prevents direct HTML injection. However, when the browser renders the DOM, the text…

  • CVE-2023-3515MedJul 5, 2023
    risk 0.22cvss 4.4epss 0.00

    Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4.

  • CVE-2026-59763MedAug 13, 2026
    risk 0.21cvss 4.3epss 0.00

    Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

  • CVE-2026-58444MedAug 13, 2026
    risk 0.21cvss 4.3epss 0.00

    Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

  • CVE-2026-58425MedAug 13, 2026
    risk 0.21cvss 4.3epss 0.00

    OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

  • CVE-2026-27783MedJul 3, 2026
    risk 0.21cvss 4.3epss 0.00

    Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.

  • CVE-2026-27761MedJul 3, 2026
    risk 0.21cvss 4.3epss 0.00

    Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.

  • CVE-2026-25714MedJul 3, 2026
    risk 0.21cvss 4.3epss 0.00

    Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.

  • CVE-2026-20888MedJan 22, 2026
    risk 0.21cvss 4.3epss 0.00

    Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.

Page 6 of 8