VYPR

Vendor CVEs

Go Gitea

All CVEs

146 total · sorted by risk
  • CVE-2022-27313HigMay 3, 2022
    risk 0.42cvss 7.5epss 0.01

    An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting the configuration file.

  • CVE-2021-39867MedOct 5, 2021
    risk 0.42cvss 6.5epss 0.01

    In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.

  • CVE-2019-10330HigMay 31, 2019
    risk 0.42cvss 7.5epss 0.02

    Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkinsfiles even if Jenkins is configured to consider them to be untrusted.

  • CVE-2026-58441MedAug 13, 2026
    risk 0.41cvss 6.3epss 0.00

    SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL

  • CVE-2026-56657MedAug 13, 2026
    risk 0.40cvss 6.2epss 0.00

    Gitea SSH Key Parser Denial of Service

  • CVE-2026-25779MedJul 3, 2026
    risk 0.40cvss 6.1epss 0.00

    Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect_to values.

  • CVE-2021-45328MedFeb 8, 2022
    risk 0.40cvss 6.1epss 0.01

    Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.

  • CVE-2026-58437HigAug 13, 2026
    risk 0.39cvss 7.1epss 0.00

    Repository Visibility Manipulation via Git Push Options

  • CVE-2026-58416HigAug 13, 2026
    risk 0.39cvss 7.1epss 0.00

    Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

  • CVE-2026-28740HigJul 3, 2026
    risk 0.39cvss 7.1epss 0.00

    Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.

  • CVE-2026-20779HigJul 3, 2026
    risk 0.39cvss 7.1epss 0.00

    Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.

  • CVE-2022-0905HigMar 10, 2022
    risk 0.39cvss 7.1epss 0.01

    Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4.

  • CVE-2026-58440MedAug 13, 2026
    risk 0.37cvss 6.8epss 0.00

    Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)

  • CVE-2022-1058MedMar 24, 2022
    risk 0.37cvss 6.1epss 0.53

    Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.

  • CVE-2026-58435MedAug 13, 2026
    risk 0.35cvss 5.4epss 0.00

    Gitea LFS Deploy-Key Privilege Escalation

  • CVE-2026-58428MedAug 13, 2026
    risk 0.35cvss 6.5epss 0.00

    Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

  • CVE-2026-57897MedAug 13, 2026
    risk 0.35cvss 6.5epss 0.00

    Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

  • CVE-2026-24059MedAug 13, 2026
    risk 0.35cvss 6.5epss 0.00

    The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked…

  • CVE-2026-58418MedJul 3, 2026
    risk 0.35cvss 6.5epss 0.00

    SSRF via HTTP Redirect in Repository Migration

  • CVE-2026-20904MedJan 22, 2026
    risk 0.35cvss 6.5epss 0.00

    Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.

  • CVE-2026-20883MedJan 22, 2026
    risk 0.35cvss 6.5epss 0.00

    Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches.

  • CVE-2026-20800MedJan 22, 2026
    risk 0.35cvss 6.5epss 0.00

    Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications.

  • CVE-2022-38795MedAug 7, 2023
    risk 0.35cvss 6.5epss 0.01

    In Gitea through 1.17.1, repo cloning can occur in the migration function.

  • CVE-2022-38183MedAug 12, 2022
    risk 0.35cvss 6.5epss 0.01

    In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to…

  • CVE-2026-56755MedAug 13, 2026
    risk 0.33cvss 6.2epss 0.00

    Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload

  • CVE-2019-1010314MedJul 11, 2019
    risk 0.33cvss 6.1epss 0.01

    Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector is: victim must navigate to public and affected repo page.

  • CVE-2026-58432MedAug 13, 2026
    risk 0.31cvss 5.9epss 0.00

    Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea

  • CVE-2026-57886MedAug 13, 2026
    risk 0.31cvss 5.9epss 0.00

    Cross-repository issue/comment attachment re-linking can expose private attachment content

  • CVE-2025-68945MedDec 26, 2025
    risk 0.31cvss 5.8epss 0.00

    In Gitea before 1.21.2, an anonymous user can visit a private user's project.

  • CVE-2026-58420MedAug 13, 2026
    risk 0.29cvss 4.4epss 0.00

    Local File Inclusion via file:// URI in Migration Restore

  • CVE-2026-58510MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

  • CVE-2026-58431MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    Public-only API token restriction is not enforced on team API routes

  • CVE-2026-55986MedAug 13, 2026
    risk 0.28cvss 5.4epss 0.00

    Email Management API Bypasses ManageCredentials Feature Restrictions

  • CVE-2026-50105MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

  • CVE-2025-68946MedDec 26, 2025
    risk 0.28cvss 5.4epss 0.00

    In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.

  • CVE-2025-68942MedDec 26, 2025
    risk 0.28cvss 5.4epss 0.00

    Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.

  • CVE-2022-1928MedMay 29, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.

  • CVE-2018-1000803MedOct 8, 2018
    risk 0.28cvss 5.3epss 0.01

    Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appear to be exploitable via Watch a repository to receive email notifications. Emails received contain the other recipients even if…

  • CVE-2026-58507MedAug 13, 2026
    risk 0.27cvss 5.3epss 0.00

    Private Repository Existence Disclosure via go-get Meta Endpoint

  • CVE-2025-69413MedJan 1, 2026
    risk 0.27cvss 5.3epss 0.00

    In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.

  • CVE-2025-68943MedDec 26, 2025
    risk 0.27cvss 5.3epss 0.00

    Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.

  • CVE-2026-59766medJul 21, 2026
    risk 0.26cvss epss

    ## Summary CVE-2026-20800 fixed private-info leakage to revoked users only for the notification endpoint. Two sibling endpoints that return data keyed on the caller's own relationship still do not re-check repo access at output time: - `GET /api/v1/user/starred` —…

  • CVE-2025-68944MedDec 26, 2025
    risk 0.26cvss 5.0epss 0.00

    Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.

  • CVE-2026-58429MedAug 13, 2026
    risk 0.25cvss 4.9epss 0.00

    Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

  • CVE-2025-68941MedDec 26, 2025
    risk 0.25cvss 4.9epss 0.00

    Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.

  • CVE-2026-52807MedJun 24, 2026
    risk 0.24cvss epss 0.00

    Gogs is an open source self-hosted Git service. Prior to 0.14.3, in new_form.tmpl, milestone names are rendered with Go's default auto-escaping ({{.Name}}), which converts < to < etc. This prevents direct HTML injection. However, when the browser renders the DOM, the text…

  • CVE-2023-3515MedJul 5, 2023
    risk 0.22cvss 4.4epss 0.00

    Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4.

  • CVE-2026-59763MedAug 13, 2026
    risk 0.21cvss 4.3epss 0.00

    Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

  • CVE-2026-58444MedAug 13, 2026
    risk 0.21cvss 4.3epss 0.00

    Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

  • CVE-2026-58425MedAug 13, 2026
    risk 0.21cvss 4.3epss 0.00

    OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)