VYPR

Vendor CVEs

Go Gitea

All CVEs

146 total · sorted by risk
  • CVE-2026-27783MedJul 3, 2026
    risk 0.21cvss 4.3epss 0.00

    Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.

  • CVE-2026-27761MedJul 3, 2026
    risk 0.21cvss 4.3epss 0.00

    Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.

  • CVE-2026-25714MedJul 3, 2026
    risk 0.21cvss 4.3epss 0.00

    Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.

  • CVE-2026-20888MedJan 22, 2026
    risk 0.21cvss 4.3epss 0.00

    Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.

  • CVE-2025-68938MedDec 26, 2025
    risk 0.21cvss 4.3epss 0.00

    Gitea before 1.25.2 mishandles authorization for deletion of releases.

  • CVE-2022-46685MedDec 12, 2022
    risk 0.21cvss 4.3epss 0.00

    In Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did not support credentials masking, potentially exposing them through the build log.

  • CVE-2026-58511LowAug 13, 2026
    risk 0.18cvss 2.7epss 0.00

    Webhook Authorization Header Returned in Plaintext via API

  • CVE-2026-58445LowAug 13, 2026
    risk 0.18cvss 2.7epss 0.00

    Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

  • CVE-2026-55984LowAug 13, 2026
    risk 0.18cvss 2.7epss 0.00

    Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

  • CVE-2026-0798LowJan 22, 2026
    risk 0.16cvss 3.5epss 0.00

    Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing…

  • CVE-2026-23603LowAug 13, 2026
    risk 0.13cvss 3.1epss 0.00

    Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

  • CVE-2025-68940LowDec 26, 2025
    risk 0.13cvss 3.1epss 0.00

    In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.

  • CVE-2019-11229HigApr 15, 2019
    risk 0.07cvss 8.8epss 0.55

    models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.

  • CVE-2026-27771HigJul 3, 2026
    risk 0.03cvss 8.2epss 0.43

    Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

  • CVE-2021-28378LowMar 15, 2021
    risk 0.01cvss 3.7epss 0.09

    Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.

  • CVE-2026-28705MedJul 3, 2026
    risk 0.00cvss 5.3epss 0.00

    Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.

  • CVE-2026-27780CriJul 3, 2026
    risk 0.00cvss 9.8epss 0.00

    Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.

  • CVE-2026-27779HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.

  • CVE-2026-27660HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.

  • CVE-2026-27657HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Gitea versions before 1.25.5 allow a user to change another user's primary email address.

  • CVE-2026-26307HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.

  • CVE-2026-26292CriJul 3, 2026
    risk 0.00cvss 9.8epss 0.00

    Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.

  • CVE-2026-26247CriJul 3, 2026
    risk 0.00cvss 9.1epss 0.00

    Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.

  • CVE-2026-26232CriJul 3, 2026
    risk 0.00cvss 9.1epss 0.00

    Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.

  • CVE-2026-25782MedJul 3, 2026
    risk 0.00cvss 5.3epss 0.00

    Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.

  • CVE-2026-25718CriJul 3, 2026
    risk 0.00cvss 9.1epss 0.00

    Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths.

  • CVE-2026-25712HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.

  • CVE-2026-24690HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.

  • CVE-2026-24451HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.

  • CVE-2026-22874CriJul 3, 2026
    risk 0.00cvss 9.6epss 0.01

    Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.

  • CVE-2026-22547CriJul 3, 2026
    risk 0.00cvss 9.1epss 0.00

    Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or object format values.

  • CVE-2026-20909MedJul 3, 2026
    risk 0.00cvss 5.3epss 0.00

    Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.

  • CVE-2026-58053CriJun 28, 2026
    risk 0.00cvss 9.9epss 0.00

    Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host,…

  • CVE-2021-29134MedMar 15, 2022
    risk 0.00cvss 5.3epss 0.01

    The avatar middleware in Gitea before 1.13.6 allows Directory Traversal via a crafted URL.

  • CVE-2021-45331CriFeb 9, 2022
    risk 0.00cvss 9.8epss 0.01

    An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.

  • CVE-2021-45330CriFeb 9, 2022
    risk 0.00cvss 9.8epss 0.01

    An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.

  • CVE-2021-45329MedFeb 8, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field.

  • CVE-2021-45326HigFeb 8, 2022
    risk 0.00cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST requests.

  • CVE-2021-45325HigFeb 8, 2022
    risk 0.00cvss 7.5epss 0.01

    Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.

  • CVE-2021-3382HigFeb 5, 2021
    risk 0.00cvss 7.5epss 0.02

    Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path.

  • CVE-2020-28991CriNov 24, 2020
    risk 0.00cvss 9.8epss 0.02

    Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go.

  • CVE-2020-13246HigMay 20, 2020
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in Gitea through 1.11.5. An attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another.

  • CVE-2019-1010261MedJul 18, 2019
    risk 0.00cvss 6.1epss 0.01

    Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execute arbitrary JS in browser. The component is: go-get URL generation - PR to fix: https://github.com/go-gitea/gitea/pull/5905. The attack vector is: victim must…

  • CVE-2019-11576CriApr 28, 2019
    risk 0.00cvss 9.8epss 0.02

    Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password.

  • CVE-2019-11228HigApr 15, 2019
    risk 0.00cvss 7.5epss 0.01

    repo/setting.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 does not validate the form.MirrorAddress before calling SaveAddress.

  • CVE-2019-1000002MedFeb 4, 2019
    risk 0.00cvss 6.5epss 0.01

    Gitea version 1.6.2 and earlier contains a Incorrect Access Control vulnerability in Delete/Edit file functionallity that can result in the attacker deleting files outside the repository he/she has access to. This attack appears to be exploitable via the attacker must get write…

Page 3 of 3