Gitea
by Go Gitea
Source repositories
CVEs (147)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-68938 | Med | 0.21 | 4.3 | 0.00 | Dec 26, 2025 | Gitea before 1.25.2 mishandles authorization for deletion of releases. | ||
| CVE-2022-46685 | Med | 0.21 | 4.3 | 0.00 | Dec 12, 2022 | In Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did not support credentials masking, potentially exposing them through the build log. | ||
| CVE-2026-58511 | Low | 0.18 | 2.7 | 0.00 | Aug 13, 2026 | Webhook Authorization Header Returned in Plaintext via API | ||
| CVE-2026-58445 | Low | 0.18 | 2.7 | 0.00 | Aug 13, 2026 | Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API | ||
| CVE-2026-55984 | Low | 0.18 | 2.7 | 0.00 | Aug 13, 2026 | Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service | ||
| CVE-2026-0798 | Low | 0.16 | 3.5 | 0.00 | Jan 22, 2026 | Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing… | ||
| CVE-2026-23603 | Low | 0.13 | 3.1 | 0.00 | Aug 13, 2026 | Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim | ||
| CVE-2025-68940 | Low | 0.13 | 3.1 | 0.00 | Dec 26, 2025 | In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request. | ||
| CVE-2019-11229 | Hig | 0.07 | 8.8 | 0.55 | Apr 15, 2019 | models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution. | ||
| CVE-2026-27771 | Hig | 0.03 | 8.2 | 0.01 | Jul 3, 2026 | Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information. | ||
| CVE-2021-28378 | Low | 0.01 | 3.7 | 0.09 | Mar 15, 2021 | Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations. | ||
| CVE-2026-24451 | Hig | 0.00 | 7.5 | 0.00 | Jul 3, 2026 | Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized. | ||
| CVE-2026-22874 | Cri | 0.00 | 9.6 | 0.00 | Jul 3, 2026 | Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering. | ||
| CVE-2026-58053 | Cri | 0.00 | 9.9 | 0.00 | Jun 28, 2026 | Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host,… | ||
| CVE-2021-29134 | Med | 0.00 | 5.3 | 0.01 | Mar 15, 2022 | The avatar middleware in Gitea before 1.13.6 allows Directory Traversal via a crafted URL. | ||
| CVE-2021-45331 | Cri | 0.00 | 9.8 | 0.01 | Feb 9, 2022 | An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once. | ||
| CVE-2021-45330 | Cri | 0.00 | 9.8 | 0.01 | Feb 9, 2022 | An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse. | ||
| CVE-2021-45329 | Med | 0.00 | 6.1 | 0.01 | Feb 8, 2022 | Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field. | ||
| CVE-2021-45326 | Hig | 0.00 | 8.8 | 0.01 | Feb 8, 2022 | Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST requests. | ||
| CVE-2021-45325 | Hig | 0.00 | 7.5 | 0.01 | Feb 8, 2022 | Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL. |
- risk 0.21cvss 4.3epss 0.00
Gitea before 1.25.2 mishandles authorization for deletion of releases.
- risk 0.21cvss 4.3epss 0.00
In Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did not support credentials masking, potentially exposing them through the build log.
- risk 0.18cvss 2.7epss 0.00
Webhook Authorization Header Returned in Plaintext via API
- risk 0.18cvss 2.7epss 0.00
Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
- risk 0.18cvss 2.7epss 0.00
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
- risk 0.16cvss 3.5epss 0.00
Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing…
- risk 0.13cvss 3.1epss 0.00
Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
- risk 0.13cvss 3.1epss 0.00
In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.
- risk 0.07cvss 8.8epss 0.55
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.
- risk 0.03cvss 8.2epss 0.01
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
- risk 0.01cvss 3.7epss 0.09
Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.
- risk 0.00cvss 7.5epss 0.00
Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.
- risk 0.00cvss 9.6epss 0.00
Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
- risk 0.00cvss 9.9epss 0.00
Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host,…
- risk 0.00cvss 5.3epss 0.01
The avatar middleware in Gitea before 1.13.6 allows Directory Traversal via a crafted URL.
- risk 0.00cvss 9.8epss 0.01
An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.
- risk 0.00cvss 9.8epss 0.01
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.
- risk 0.00cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field.
- risk 0.00cvss 8.8epss 0.01
Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST requests.
- risk 0.00cvss 7.5epss 0.01
Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.
Page 7 of 8