VYPR

Gitea

by Go Gitea

Source repositories

CVEs (147)

  • CVE-2026-0798LowJan 22, 2026
    risk 0.16cvss 3.5epss 0.00

    Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing…

  • CVE-2026-23603LowAug 13, 2026
    risk 0.13cvss 3.1epss 0.00

    Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

  • CVE-2025-68940LowDec 26, 2025
    risk 0.13cvss 3.1epss 0.00

    In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.

  • CVE-2026-27771HigJul 3, 2026
    risk 0.03cvss 8.2epss 0.01

    Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

  • CVE-2026-24451HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.

  • CVE-2026-22874CriJul 3, 2026
    risk 0.00cvss 9.6epss 0.00

    Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.

  • CVE-2026-58053CriJun 28, 2026
    risk 0.00cvss 9.9epss 0.00

    Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host,…

Page 8 of 8