Vendor CVEs
Go Gitea
All CVEs
146 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-27313 | Hig | 0.42 | 7.5 | 0.01 | May 3, 2022 | An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting the configuration file. | ||
| CVE-2021-39867 | Med | 0.42 | 6.5 | 0.01 | Oct 5, 2021 | In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks. | ||
| CVE-2019-10330 | Hig | 0.42 | 7.5 | 0.02 | May 31, 2019 | Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkinsfiles even if Jenkins is configured to consider them to be untrusted. | ||
| CVE-2026-58441 | Med | 0.41 | 6.3 | 0.00 | Aug 13, 2026 | SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL | ||
| CVE-2026-56657 | Med | 0.40 | 6.2 | 0.00 | Aug 13, 2026 | Gitea SSH Key Parser Denial of Service | ||
| CVE-2026-25779 | Med | 0.40 | 6.1 | 0.00 | Jul 3, 2026 | Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect_to values. | ||
| CVE-2021-45328 | Med | 0.40 | 6.1 | 0.01 | Feb 8, 2022 | Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs. | ||
| CVE-2026-58437 | Hig | 0.39 | 7.1 | 0.00 | Aug 13, 2026 | Repository Visibility Manipulation via Git Push Options | ||
| CVE-2026-58416 | Hig | 0.39 | 7.1 | 0.00 | Aug 13, 2026 | Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) | ||
| CVE-2026-28740 | Hig | 0.39 | 7.1 | 0.00 | Jul 3, 2026 | Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access. | ||
| CVE-2026-20779 | Hig | 0.39 | 7.1 | 0.00 | Jul 3, 2026 | Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path. | ||
| CVE-2022-0905 | Hig | 0.39 | 7.1 | 0.01 | Mar 10, 2022 | Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4. | ||
| CVE-2026-58440 | Med | 0.37 | 6.8 | 0.00 | Aug 13, 2026 | Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`) | ||
| CVE-2022-1058 | Med | 0.37 | 6.1 | 0.53 | Mar 24, 2022 | Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5. | ||
| CVE-2026-58435 | Med | 0.35 | 5.4 | 0.00 | Aug 13, 2026 | Gitea LFS Deploy-Key Privilege Escalation | ||
| CVE-2026-58428 | Med | 0.35 | 6.5 | 0.00 | Aug 13, 2026 | Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) | ||
| CVE-2026-57897 | Med | 0.35 | 6.5 | 0.00 | Aug 13, 2026 | Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs | ||
| CVE-2026-24059 | Med | 0.35 | 6.5 | 0.00 | Aug 13, 2026 | The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked… | ||
| CVE-2026-58418 | Med | 0.35 | 6.5 | 0.00 | Jul 3, 2026 | SSRF via HTTP Redirect in Repository Migration | ||
| CVE-2026-20904 | Med | 0.35 | 6.5 | 0.00 | Jan 22, 2026 | Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. | ||
| CVE-2026-20883 | Med | 0.35 | 6.5 | 0.00 | Jan 22, 2026 | Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. | ||
| CVE-2026-20800 | Med | 0.35 | 6.5 | 0.00 | Jan 22, 2026 | Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. | ||
| CVE-2022-38795 | Med | 0.35 | 6.5 | 0.01 | Aug 7, 2023 | In Gitea through 1.17.1, repo cloning can occur in the migration function. | ||
| CVE-2022-38183 | Med | 0.35 | 6.5 | 0.01 | Aug 12, 2022 | In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to… | ||
| CVE-2026-56755 | Med | 0.33 | 6.2 | 0.00 | Aug 13, 2026 | Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload | ||
| CVE-2019-1010314 | Med | 0.33 | 6.1 | 0.01 | Jul 11, 2019 | Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector is: victim must navigate to public and affected repo page. | ||
| CVE-2026-58432 | Med | 0.31 | 5.9 | 0.00 | Aug 13, 2026 | Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea | ||
| CVE-2026-57886 | Med | 0.31 | 5.9 | 0.00 | Aug 13, 2026 | Cross-repository issue/comment attachment re-linking can expose private attachment content | ||
| CVE-2025-68945 | Med | 0.31 | 5.8 | 0.00 | Dec 26, 2025 | In Gitea before 1.21.2, an anonymous user can visit a private user's project. | ||
| CVE-2026-58420 | Med | 0.29 | 4.4 | 0.00 | Aug 13, 2026 | Local File Inclusion via file:// URI in Migration Restore | ||
| CVE-2026-58510 | Med | 0.28 | 4.3 | 0.00 | Aug 13, 2026 | GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private | ||
| CVE-2026-58431 | Med | 0.28 | 4.3 | 0.00 | Aug 13, 2026 | Public-only API token restriction is not enforced on team API routes | ||
| CVE-2026-55986 | Med | 0.28 | 5.4 | 0.00 | Aug 13, 2026 | Email Management API Bypasses ManageCredentials Feature Restrictions | ||
| CVE-2026-50105 | Med | 0.28 | 4.3 | 0.00 | Aug 13, 2026 | RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) | ||
| CVE-2025-68946 | Med | 0.28 | 5.4 | 0.00 | Dec 26, 2025 | In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS. | ||
| CVE-2025-68942 | Med | 0.28 | 5.4 | 0.00 | Dec 26, 2025 | Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text. | ||
| CVE-2022-1928 | Med | 0.28 | 5.4 | 0.01 | May 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9. | ||
| CVE-2018-1000803 | Med | 0.28 | 5.3 | 0.01 | Oct 8, 2018 | Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appear to be exploitable via Watch a repository to receive email notifications. Emails received contain the other recipients even if… | ||
| CVE-2026-58507 | Med | 0.27 | 5.3 | 0.00 | Aug 13, 2026 | Private Repository Existence Disclosure via go-get Meta Endpoint | ||
| CVE-2025-69413 | Med | 0.27 | 5.3 | 0.00 | Jan 1, 2026 | In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists. | ||
| CVE-2025-68943 | Med | 0.27 | 5.3 | 0.00 | Dec 26, 2025 | Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order. | ||
| CVE-2026-59766 | med | 0.26 | — | — | Jul 21, 2026 | ## Summary CVE-2026-20800 fixed private-info leakage to revoked users only for the notification endpoint. Two sibling endpoints that return data keyed on the caller's own relationship still do not re-check repo access at output time: - `GET /api/v1/user/starred` —… | ||
| CVE-2025-68944 | Med | 0.26 | 5.0 | 0.00 | Dec 26, 2025 | Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries. | ||
| CVE-2026-58429 | Med | 0.25 | 4.9 | 0.00 | Aug 13, 2026 | Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints | ||
| CVE-2025-68941 | Med | 0.25 | 4.9 | 0.00 | Dec 26, 2025 | Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources. | ||
| CVE-2026-52807 | Med | 0.24 | — | 0.00 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, in new_form.tmpl, milestone names are rendered with Go's default auto-escaping ({{.Name}}), which converts < to < etc. This prevents direct HTML injection. However, when the browser renders the DOM, the text… | ||
| CVE-2023-3515 | Med | 0.22 | 4.4 | 0.00 | Jul 5, 2023 | Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4. | ||
| CVE-2026-59763 | Med | 0.21 | 4.3 | 0.00 | Aug 13, 2026 | Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads | ||
| CVE-2026-58444 | Med | 0.21 | 4.3 | 0.00 | Aug 13, 2026 | Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents | ||
| CVE-2026-58425 | Med | 0.21 | 4.3 | 0.00 | Aug 13, 2026 | OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) |
- risk 0.42cvss 7.5epss 0.01
An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting the configuration file.
- risk 0.42cvss 6.5epss 0.01
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
- risk 0.42cvss 7.5epss 0.02
Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkinsfiles even if Jenkins is configured to consider them to be untrusted.
- risk 0.41cvss 6.3epss 0.00
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
- risk 0.40cvss 6.2epss 0.00
Gitea SSH Key Parser Denial of Service
- risk 0.40cvss 6.1epss 0.00
Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect_to values.
- risk 0.40cvss 6.1epss 0.01
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
- risk 0.39cvss 7.1epss 0.00
Repository Visibility Manipulation via Git Push Options
- risk 0.39cvss 7.1epss 0.00
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
- risk 0.39cvss 7.1epss 0.00
Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.
- risk 0.39cvss 7.1epss 0.00
Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.
- risk 0.39cvss 7.1epss 0.01
Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4.
- risk 0.37cvss 6.8epss 0.00
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)
- risk 0.37cvss 6.1epss 0.53
Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.
- risk 0.35cvss 5.4epss 0.00
Gitea LFS Deploy-Key Privilege Escalation
- risk 0.35cvss 6.5epss 0.00
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
- risk 0.35cvss 6.5epss 0.00
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
- risk 0.35cvss 6.5epss 0.00
The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked…
- risk 0.35cvss 6.5epss 0.00
SSRF via HTTP Redirect in Repository Migration
- risk 0.35cvss 6.5epss 0.00
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.
- risk 0.35cvss 6.5epss 0.00
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches.
- risk 0.35cvss 6.5epss 0.00
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications.
- risk 0.35cvss 6.5epss 0.01
In Gitea through 1.17.1, repo cloning can occur in the migration function.
- risk 0.35cvss 6.5epss 0.01
In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to…
- risk 0.33cvss 6.2epss 0.00
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
- risk 0.33cvss 6.1epss 0.01
Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector is: victim must navigate to public and affected repo page.
- risk 0.31cvss 5.9epss 0.00
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
- risk 0.31cvss 5.9epss 0.00
Cross-repository issue/comment attachment re-linking can expose private attachment content
- risk 0.31cvss 5.8epss 0.00
In Gitea before 1.21.2, an anonymous user can visit a private user's project.
- risk 0.29cvss 4.4epss 0.00
Local File Inclusion via file:// URI in Migration Restore
- risk 0.28cvss 4.3epss 0.00
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
- risk 0.28cvss 4.3epss 0.00
Public-only API token restriction is not enforced on team API routes
- risk 0.28cvss 5.4epss 0.00
Email Management API Bypasses ManageCredentials Feature Restrictions
- risk 0.28cvss 4.3epss 0.00
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
- risk 0.28cvss 5.4epss 0.00
In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.
- risk 0.28cvss 5.4epss 0.00
Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.
- risk 0.28cvss 5.3epss 0.01
Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appear to be exploitable via Watch a repository to receive email notifications. Emails received contain the other recipients even if…
- risk 0.27cvss 5.3epss 0.00
Private Repository Existence Disclosure via go-get Meta Endpoint
- risk 0.27cvss 5.3epss 0.00
In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.
- risk 0.27cvss 5.3epss 0.00
Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.
- risk 0.26cvss —epss —
## Summary CVE-2026-20800 fixed private-info leakage to revoked users only for the notification endpoint. Two sibling endpoints that return data keyed on the caller's own relationship still do not re-check repo access at output time: - `GET /api/v1/user/starred` —…
- risk 0.26cvss 5.0epss 0.00
Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.
- risk 0.25cvss 4.9epss 0.00
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
- risk 0.25cvss 4.9epss 0.00
Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.
- risk 0.24cvss —epss 0.00
Gogs is an open source self-hosted Git service. Prior to 0.14.3, in new_form.tmpl, milestone names are rendered with Go's default auto-escaping ({{.Name}}), which converts < to < etc. This prevents direct HTML injection. However, when the browser renders the DOM, the text…
- risk 0.22cvss 4.4epss 0.00
Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4.
- risk 0.21cvss 4.3epss 0.00
Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
- risk 0.21cvss 4.3epss 0.00
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
- risk 0.21cvss 4.3epss 0.00
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
Page 2 of 3