Gitea
by Go Gitea
Source repositories
CVEs (147)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-0798 | Low | 0.16 | 3.5 | 0.00 | Jan 22, 2026 | Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing… | ||
| CVE-2026-23603 | Low | 0.13 | 3.1 | 0.00 | Aug 13, 2026 | Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim | ||
| CVE-2025-68940 | Low | 0.13 | 3.1 | 0.00 | Dec 26, 2025 | In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request. | ||
| CVE-2026-27771 | Hig | 0.03 | 8.2 | 0.01 | Jul 3, 2026 | Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information. | ||
| CVE-2026-24451 | Hig | 0.00 | 7.5 | 0.00 | Jul 3, 2026 | Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized. | ||
| CVE-2026-22874 | Cri | 0.00 | 9.6 | 0.00 | Jul 3, 2026 | Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering. | ||
| CVE-2026-58053 | Cri | 0.00 | 9.9 | 0.00 | Jun 28, 2026 | Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host,… |
- risk 0.16cvss 3.5epss 0.00
Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing…
- risk 0.13cvss 3.1epss 0.00
Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
- risk 0.13cvss 3.1epss 0.00
In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.
- risk 0.03cvss 8.2epss 0.01
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
- risk 0.00cvss 7.5epss 0.00
Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.
- risk 0.00cvss 9.6epss 0.00
Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
- risk 0.00cvss 9.9epss 0.00
Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host,…
Page 8 of 8