Vendor CVEs
Go Gitea
All CVEs
147 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-1000803 | Med | 0.28 | 5.3 | 0.01 | Oct 8, 2018 | Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appear to be exploitable via Watch a repository to receive email notifications. Emails received contain the other recipients even if… | ||
| CVE-2026-58507 | Med | 0.27 | 5.3 | 0.00 | Aug 13, 2026 | Private Repository Existence Disclosure via go-get Meta Endpoint | ||
| CVE-2026-28705 | Med | 0.27 | 5.3 | 0.00 | Jul 3, 2026 | Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths. | ||
| CVE-2026-25782 | Med | 0.27 | 5.3 | 0.00 | Jul 3, 2026 | Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue. | ||
| CVE-2026-20909 | Med | 0.27 | 5.3 | 0.00 | Jul 3, 2026 | Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries. | ||
| CVE-2025-69413 | Med | 0.27 | 5.3 | 0.00 | Jan 1, 2026 | In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists. | ||
| CVE-2025-68943 | Med | 0.27 | 5.3 | 0.00 | Dec 26, 2025 | Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order. | ||
| CVE-2026-59766 | med | 0.26 | — | — | Jul 21, 2026 | ## Summary CVE-2026-20800 fixed private-info leakage to revoked users only for the notification endpoint. Two sibling endpoints that return data keyed on the caller's own relationship still do not re-check repo access at output time: - `GET /api/v1/user/starred` —… | ||
| CVE-2025-68944 | Med | 0.26 | 5.0 | 0.00 | Dec 26, 2025 | Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries. | ||
| CVE-2026-58429 | Med | 0.25 | 4.9 | 0.00 | Aug 13, 2026 | Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints | ||
| CVE-2025-68941 | Med | 0.25 | 4.9 | 0.00 | Dec 26, 2025 | Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources. | ||
| CVE-2026-52807 | Med | 0.24 | — | 0.00 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, in new_form.tmpl, milestone names are rendered with Go's default auto-escaping ({{.Name}}), which converts < to < etc. This prevents direct HTML injection. However, when the browser renders the DOM, the text… | ||
| CVE-2023-3515 | Med | 0.22 | 4.4 | 0.00 | Jul 5, 2023 | Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4. | ||
| CVE-2026-59763 | Med | 0.21 | 4.3 | 0.00 | Aug 13, 2026 | Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads | ||
| CVE-2026-58444 | Med | 0.21 | 4.3 | 0.00 | Aug 13, 2026 | Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents | ||
| CVE-2026-58425 | Med | 0.21 | 4.3 | 0.00 | Aug 13, 2026 | OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) | ||
| CVE-2026-27783 | Med | 0.21 | 4.3 | 0.00 | Jul 3, 2026 | Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints. | ||
| CVE-2026-27761 | Med | 0.21 | 4.3 | 0.00 | Jul 3, 2026 | Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope. | ||
| CVE-2026-25714 | Med | 0.21 | 4.3 | 0.00 | Jul 3, 2026 | Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941. | ||
| CVE-2026-20888 | Med | 0.21 | 4.3 | 0.00 | Jan 22, 2026 | Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. | ||
| CVE-2025-68938 | Med | 0.21 | 4.3 | 0.00 | Dec 26, 2025 | Gitea before 1.25.2 mishandles authorization for deletion of releases. | ||
| CVE-2022-46685 | Med | 0.21 | 4.3 | 0.00 | Dec 12, 2022 | In Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did not support credentials masking, potentially exposing them through the build log. | ||
| CVE-2026-58511 | Low | 0.18 | 2.7 | 0.00 | Aug 13, 2026 | Webhook Authorization Header Returned in Plaintext via API | ||
| CVE-2026-58445 | Low | 0.18 | 2.7 | 0.00 | Aug 13, 2026 | Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API | ||
| CVE-2026-55984 | Low | 0.18 | 2.7 | 0.00 | Aug 13, 2026 | Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service | ||
| CVE-2026-0798 | Low | 0.16 | 3.5 | 0.00 | Jan 22, 2026 | Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing… | ||
| CVE-2026-23603 | Low | 0.13 | 3.1 | 0.00 | Aug 13, 2026 | Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim | ||
| CVE-2025-68940 | Low | 0.13 | 3.1 | 0.00 | Dec 26, 2025 | In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request. | ||
| CVE-2019-11229 | Hig | 0.07 | 8.8 | 0.55 | Apr 15, 2019 | models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution. | ||
| CVE-2026-27771 | Hig | 0.03 | 8.2 | 0.01 | Jul 3, 2026 | Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information. | ||
| CVE-2021-28378 | Low | 0.01 | 3.7 | 0.09 | Mar 15, 2021 | Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations. | ||
| CVE-2026-24451 | Hig | 0.00 | 7.5 | 0.00 | Jul 3, 2026 | Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized. | ||
| CVE-2026-22874 | Cri | 0.00 | 9.6 | 0.00 | Jul 3, 2026 | Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering. | ||
| CVE-2026-58053 | Cri | 0.00 | 9.9 | 0.00 | Jun 28, 2026 | Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host,… | ||
| CVE-2021-29134 | Med | 0.00 | 5.3 | 0.01 | Mar 15, 2022 | The avatar middleware in Gitea before 1.13.6 allows Directory Traversal via a crafted URL. | ||
| CVE-2021-45331 | Cri | 0.00 | 9.8 | 0.01 | Feb 9, 2022 | An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once. | ||
| CVE-2021-45330 | Cri | 0.00 | 9.8 | 0.01 | Feb 9, 2022 | An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse. | ||
| CVE-2021-45329 | Med | 0.00 | 6.1 | 0.01 | Feb 8, 2022 | Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field. | ||
| CVE-2021-45326 | Hig | 0.00 | 8.8 | 0.01 | Feb 8, 2022 | Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST requests. | ||
| CVE-2021-45325 | Hig | 0.00 | 7.5 | 0.01 | Feb 8, 2022 | Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL. | ||
| CVE-2021-3382 | Hig | 0.00 | 7.5 | 0.02 | Feb 5, 2021 | Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path. | ||
| CVE-2020-28991 | Cri | 0.00 | 9.8 | 0.02 | Nov 24, 2020 | Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. | ||
| CVE-2020-13246 | Hig | 0.00 | 7.5 | 0.02 | May 20, 2020 | An issue was discovered in Gitea through 1.11.5. An attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. | ||
| CVE-2019-1010261 | Med | 0.00 | 6.1 | 0.01 | Jul 18, 2019 | Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execute arbitrary JS in browser. The component is: go-get URL generation - PR to fix: https://github.com/go-gitea/gitea/pull/5905. The attack vector is: victim must… | ||
| CVE-2019-11576 | Cri | 0.00 | 9.8 | 0.02 | Apr 28, 2019 | Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password. | ||
| CVE-2019-11228 | Hig | 0.00 | 7.5 | 0.01 | Apr 15, 2019 | repo/setting.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 does not validate the form.MirrorAddress before calling SaveAddress. | ||
| CVE-2019-1000002 | Med | 0.00 | 6.5 | 0.01 | Feb 4, 2019 | Gitea version 1.6.2 and earlier contains a Incorrect Access Control vulnerability in Delete/Edit file functionallity that can result in the attacker deleting files outside the repository he/she has access to. This attack appears to be exploitable via the attacker must get write… |
- risk 0.28cvss 5.3epss 0.01
Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appear to be exploitable via Watch a repository to receive email notifications. Emails received contain the other recipients even if…
- risk 0.27cvss 5.3epss 0.00
Private Repository Existence Disclosure via go-get Meta Endpoint
- risk 0.27cvss 5.3epss 0.00
Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.
- risk 0.27cvss 5.3epss 0.00
Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.
- risk 0.27cvss 5.3epss 0.00
Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
- risk 0.27cvss 5.3epss 0.00
In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.
- risk 0.27cvss 5.3epss 0.00
Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.
- risk 0.26cvss —epss —
## Summary CVE-2026-20800 fixed private-info leakage to revoked users only for the notification endpoint. Two sibling endpoints that return data keyed on the caller's own relationship still do not re-check repo access at output time: - `GET /api/v1/user/starred` —…
- risk 0.26cvss 5.0epss 0.00
Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.
- risk 0.25cvss 4.9epss 0.00
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
- risk 0.25cvss 4.9epss 0.00
Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.
- risk 0.24cvss —epss 0.00
Gogs is an open source self-hosted Git service. Prior to 0.14.3, in new_form.tmpl, milestone names are rendered with Go's default auto-escaping ({{.Name}}), which converts < to < etc. This prevents direct HTML injection. However, when the browser renders the DOM, the text…
- risk 0.22cvss 4.4epss 0.00
Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4.
- risk 0.21cvss 4.3epss 0.00
Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
- risk 0.21cvss 4.3epss 0.00
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
- risk 0.21cvss 4.3epss 0.00
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
- risk 0.21cvss 4.3epss 0.00
Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.
- risk 0.21cvss 4.3epss 0.00
Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.
- risk 0.21cvss 4.3epss 0.00
Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.
- risk 0.21cvss 4.3epss 0.00
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.
- risk 0.21cvss 4.3epss 0.00
Gitea before 1.25.2 mishandles authorization for deletion of releases.
- risk 0.21cvss 4.3epss 0.00
In Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did not support credentials masking, potentially exposing them through the build log.
- risk 0.18cvss 2.7epss 0.00
Webhook Authorization Header Returned in Plaintext via API
- risk 0.18cvss 2.7epss 0.00
Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
- risk 0.18cvss 2.7epss 0.00
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
- risk 0.16cvss 3.5epss 0.00
Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing…
- risk 0.13cvss 3.1epss 0.00
Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
- risk 0.13cvss 3.1epss 0.00
In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.
- risk 0.07cvss 8.8epss 0.55
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.
- risk 0.03cvss 8.2epss 0.01
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
- risk 0.01cvss 3.7epss 0.09
Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.
- risk 0.00cvss 7.5epss 0.00
Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.
- risk 0.00cvss 9.6epss 0.00
Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
- risk 0.00cvss 9.9epss 0.00
Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host,…
- risk 0.00cvss 5.3epss 0.01
The avatar middleware in Gitea before 1.13.6 allows Directory Traversal via a crafted URL.
- risk 0.00cvss 9.8epss 0.01
An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.
- risk 0.00cvss 9.8epss 0.01
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.
- risk 0.00cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field.
- risk 0.00cvss 8.8epss 0.01
Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST requests.
- risk 0.00cvss 7.5epss 0.01
Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.
- risk 0.00cvss 7.5epss 0.02
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path.
- risk 0.00cvss 9.8epss 0.02
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go.
- risk 0.00cvss 7.5epss 0.02
An issue was discovered in Gitea through 1.11.5. An attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another.
- risk 0.00cvss 6.1epss 0.01
Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execute arbitrary JS in browser. The component is: go-get URL generation - PR to fix: https://github.com/go-gitea/gitea/pull/5905. The attack vector is: victim must…
- risk 0.00cvss 9.8epss 0.02
Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password.
- risk 0.00cvss 7.5epss 0.01
repo/setting.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 does not validate the form.MirrorAddress before calling SaveAddress.
- risk 0.00cvss 6.5epss 0.01
Gitea version 1.6.2 and earlier contains a Incorrect Access Control vulnerability in Delete/Edit file functionallity that can result in the attacker deleting files outside the repository he/she has access to. This attack appears to be exploitable via the attacker must get write…
Page 3 of 3