Vendor CVEs
Go Gitea
All CVEs
147 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-58417 | Hig | 0.42 | 7.5 | 0.00 | Aug 13, 2026 | REST API exposes organization membership of private organizations to public | ||
| CVE-2026-42931 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2026 | Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint | ||
| CVE-2026-34966 | Hig | 0.42 | 7.6 | 0.00 | Aug 5, 2026 | Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext.… | ||
| CVE-2026-58421 | Hig | 0.42 | 7.5 | 0.01 | Jul 3, 2026 | Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service | ||
| CVE-2026-58419 | Hig | 0.42 | 7.5 | 0.01 | Jul 3, 2026 | Notification API leaks private issue metadata after access revocation | ||
| CVE-2026-27779 | Hig | 0.42 | 7.5 | 0.01 | Jul 3, 2026 | Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation. | ||
| CVE-2026-27660 | Hig | 0.42 | 7.5 | 0.00 | Jul 3, 2026 | Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission. | ||
| CVE-2026-27657 | Hig | 0.42 | 7.5 | 0.00 | Jul 3, 2026 | Gitea versions before 1.25.5 allow a user to change another user's primary email address. | ||
| CVE-2026-26307 | Hig | 0.42 | 7.5 | 0.01 | Jul 3, 2026 | Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources. | ||
| CVE-2026-25712 | Hig | 0.42 | 7.5 | 0.00 | Jul 3, 2026 | Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations. | ||
| CVE-2026-25038 | Hig | 0.42 | 7.5 | 0.00 | Jul 3, 2026 | Gitea 1.26.2 allows unauthorized users to access labels of private organizations. | ||
| CVE-2026-24690 | Hig | 0.42 | 7.5 | 0.00 | Jul 3, 2026 | Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches. | ||
| CVE-2026-20736 | Hig | 0.42 | 7.5 | 0.00 | Jan 22, 2026 | Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a different repository they can access. | ||
| CVE-2022-27313 | Hig | 0.42 | 7.5 | 0.01 | May 3, 2022 | An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting the configuration file. | ||
| CVE-2021-39867 | Med | 0.42 | 6.5 | 0.01 | Oct 5, 2021 | In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks. | ||
| CVE-2019-10330 | Hig | 0.42 | 7.5 | 0.02 | May 31, 2019 | Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkinsfiles even if Jenkins is configured to consider them to be untrusted. | ||
| CVE-2026-58441 | Med | 0.41 | 6.3 | 0.00 | Aug 13, 2026 | SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL | ||
| CVE-2026-56657 | Med | 0.40 | 6.2 | 0.00 | Aug 13, 2026 | Gitea SSH Key Parser Denial of Service | ||
| CVE-2026-25779 | Med | 0.40 | 6.1 | 0.00 | Jul 3, 2026 | Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect_to values. | ||
| CVE-2026-58437 | Hig | 0.39 | 7.1 | 0.00 | Aug 13, 2026 | Repository Visibility Manipulation via Git Push Options | ||
| CVE-2026-58416 | Hig | 0.39 | 7.1 | 0.00 | Aug 13, 2026 | Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) | ||
| CVE-2026-28740 | Hig | 0.39 | 7.1 | 0.00 | Jul 3, 2026 | Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access. | ||
| CVE-2026-20779 | Hig | 0.39 | 7.1 | 0.00 | Jul 3, 2026 | Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path. | ||
| CVE-2022-0905 | Hig | 0.39 | 7.1 | 0.01 | Mar 10, 2022 | Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4. | ||
| CVE-2026-58440 | Med | 0.37 | 6.8 | 0.00 | Aug 13, 2026 | Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`) | ||
| CVE-2022-1058 | Med | 0.37 | 6.1 | 0.53 | Mar 24, 2022 | Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5. | ||
| CVE-2026-58435 | Med | 0.35 | 5.4 | 0.00 | Aug 13, 2026 | Gitea LFS Deploy-Key Privilege Escalation | ||
| CVE-2026-58428 | Med | 0.35 | 6.5 | 0.00 | Aug 13, 2026 | Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) | ||
| CVE-2026-57897 | Med | 0.35 | 6.5 | 0.00 | Aug 13, 2026 | Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs | ||
| CVE-2026-24059 | Med | 0.35 | 6.5 | 0.00 | Aug 13, 2026 | The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked… | ||
| CVE-2026-58418 | Med | 0.35 | 6.5 | 0.00 | Jul 3, 2026 | SSRF via HTTP Redirect in Repository Migration | ||
| CVE-2026-20904 | Med | 0.35 | 6.5 | 0.00 | Jan 22, 2026 | Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. | ||
| CVE-2026-20883 | Med | 0.35 | 6.5 | 0.00 | Jan 22, 2026 | Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. | ||
| CVE-2026-20800 | Med | 0.35 | 6.5 | 0.00 | Jan 22, 2026 | Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. | ||
| CVE-2022-38795 | Med | 0.35 | 6.5 | 0.01 | Aug 7, 2023 | In Gitea through 1.17.1, repo cloning can occur in the migration function. | ||
| CVE-2022-38183 | Med | 0.35 | 6.5 | 0.01 | Aug 12, 2022 | In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to… | ||
| CVE-2026-56755 | Med | 0.33 | 6.2 | 0.00 | Aug 13, 2026 | Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload | ||
| CVE-2021-45328 | Med | 0.33 | 6.1 | 0.01 | Feb 8, 2022 | Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs. | ||
| CVE-2019-1010314 | Med | 0.33 | 6.1 | 0.01 | Jul 11, 2019 | Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector is: victim must navigate to public and affected repo page. | ||
| CVE-2026-58432 | Med | 0.31 | 5.9 | 0.00 | Aug 13, 2026 | Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea | ||
| CVE-2026-57886 | Med | 0.31 | 5.9 | 0.00 | Aug 13, 2026 | Cross-repository issue/comment attachment re-linking can expose private attachment content | ||
| CVE-2025-68945 | Med | 0.31 | 5.8 | 0.00 | Dec 26, 2025 | In Gitea before 1.21.2, an anonymous user can visit a private user's project. | ||
| CVE-2026-58420 | Med | 0.29 | 4.4 | 0.00 | Aug 13, 2026 | Local File Inclusion via file:// URI in Migration Restore | ||
| CVE-2026-58510 | Med | 0.28 | 4.3 | 0.00 | Aug 13, 2026 | GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private | ||
| CVE-2026-58431 | Med | 0.28 | 4.3 | 0.00 | Aug 13, 2026 | Public-only API token restriction is not enforced on team API routes | ||
| CVE-2026-55986 | Med | 0.28 | 5.4 | 0.00 | Aug 13, 2026 | Email Management API Bypasses ManageCredentials Feature Restrictions | ||
| CVE-2026-50105 | Med | 0.28 | 4.3 | 0.00 | Aug 13, 2026 | RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) | ||
| CVE-2025-68946 | Med | 0.28 | 5.4 | 0.00 | Dec 26, 2025 | In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS. | ||
| CVE-2025-68942 | Med | 0.28 | 5.4 | 0.00 | Dec 26, 2025 | Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text. | ||
| CVE-2022-1928 | Med | 0.28 | 5.4 | 0.01 | May 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9. |
- risk 0.42cvss 7.5epss 0.00
REST API exposes organization membership of private organizations to public
- risk 0.42cvss 6.5epss 0.00
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
- risk 0.42cvss 7.6epss 0.00
Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext.…
- risk 0.42cvss 7.5epss 0.01
Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
- risk 0.42cvss 7.5epss 0.01
Notification API leaks private issue metadata after access revocation
- risk 0.42cvss 7.5epss 0.01
Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
- risk 0.42cvss 7.5epss 0.00
Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.
- risk 0.42cvss 7.5epss 0.00
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
- risk 0.42cvss 7.5epss 0.01
Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.
- risk 0.42cvss 7.5epss 0.00
Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.
- risk 0.42cvss 7.5epss 0.00
Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
- risk 0.42cvss 7.5epss 0.00
Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
- risk 0.42cvss 7.5epss 0.00
Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a different repository they can access.
- risk 0.42cvss 7.5epss 0.01
An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting the configuration file.
- risk 0.42cvss 6.5epss 0.01
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
- risk 0.42cvss 7.5epss 0.02
Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkinsfiles even if Jenkins is configured to consider them to be untrusted.
- risk 0.41cvss 6.3epss 0.00
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
- risk 0.40cvss 6.2epss 0.00
Gitea SSH Key Parser Denial of Service
- risk 0.40cvss 6.1epss 0.00
Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect_to values.
- risk 0.39cvss 7.1epss 0.00
Repository Visibility Manipulation via Git Push Options
- risk 0.39cvss 7.1epss 0.00
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
- risk 0.39cvss 7.1epss 0.00
Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.
- risk 0.39cvss 7.1epss 0.00
Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.
- risk 0.39cvss 7.1epss 0.01
Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4.
- risk 0.37cvss 6.8epss 0.00
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)
- risk 0.37cvss 6.1epss 0.53
Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.
- risk 0.35cvss 5.4epss 0.00
Gitea LFS Deploy-Key Privilege Escalation
- risk 0.35cvss 6.5epss 0.00
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
- risk 0.35cvss 6.5epss 0.00
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
- risk 0.35cvss 6.5epss 0.00
The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked…
- risk 0.35cvss 6.5epss 0.00
SSRF via HTTP Redirect in Repository Migration
- risk 0.35cvss 6.5epss 0.00
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.
- risk 0.35cvss 6.5epss 0.00
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches.
- risk 0.35cvss 6.5epss 0.00
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications.
- risk 0.35cvss 6.5epss 0.01
In Gitea through 1.17.1, repo cloning can occur in the migration function.
- risk 0.35cvss 6.5epss 0.01
In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to…
- risk 0.33cvss 6.2epss 0.00
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
- risk 0.33cvss 6.1epss 0.01
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
- risk 0.33cvss 6.1epss 0.01
Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector is: victim must navigate to public and affected repo page.
- risk 0.31cvss 5.9epss 0.00
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
- risk 0.31cvss 5.9epss 0.00
Cross-repository issue/comment attachment re-linking can expose private attachment content
- risk 0.31cvss 5.8epss 0.00
In Gitea before 1.21.2, an anonymous user can visit a private user's project.
- risk 0.29cvss 4.4epss 0.00
Local File Inclusion via file:// URI in Migration Restore
- risk 0.28cvss 4.3epss 0.00
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
- risk 0.28cvss 4.3epss 0.00
Public-only API token restriction is not enforced on team API routes
- risk 0.28cvss 5.4epss 0.00
Email Management API Bypasses ManageCredentials Feature Restrictions
- risk 0.28cvss 4.3epss 0.00
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
- risk 0.28cvss 5.4epss 0.00
In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.
- risk 0.28cvss 5.4epss 0.00
Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.
Page 2 of 3