Gitea Open Source Git Server vulnerabilities
92 known vulnerabilities affecting gitea/gitea_open_source_git_server.
Total CVEs
92
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL21HIGH34MEDIUM32LOW5
Vulnerabilities
Page 2 of 5
CVE-2026-58426P3CRITICALCVSS 9.6≥ 1.22.0, ≤ 1.26.12026-07-03
CVE-2026-58426 [CRITICAL] CWE-347 CVE-2026-58426: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
nvd
CVE-2026-25718P3CRITICALCVSS 9.1fixed in 1.25.52026-07-03
CVE-2026-25718 [CRITICAL] CWE-59 CVE-2026-25718: Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowi
Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths.
nvd
CVE-2026-22555P3HIGHCVSS 8.1fixed in 1.26.02026-07-03
CVE-2026-22555 [HIGH] CWE-284 CVE-2026-22555: Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.
nvd
CVE-2026-56750P3CRITICALCVSS 9.1≤ 1.26.42026-08-13
CVE-2026-56750 [CRITICAL] CWE-284 CVE-2026-56750: Gitea Remember-Me Token Theft Not Invalidating Attacker Session
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
nvd
CVE-2026-20912P3CRITICALCVSS 9.1≤ 1.25.32026-01-22
CVE-2026-20912 [CRITICAL] CWE-284 CVE-2026-20912: Gitea does not properly validate repository ownership when linking attachments to releases. An attac
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users.
nvd
CVE-2026-28744P3HIGHCVSS 8.1≤ 1.26.12026-07-03
CVE-2026-28744 [HIGH] CWE-863 CVE-2026-28744: Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer to
Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.
nvd
CVE-2026-57894P3HIGHCVSS 8.5≤ 1.26.42026-08-13
CVE-2026-57894 [HIGH] CWE-918 CVE-2026-57894: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
nvd
CVE-2026-58433P3CRITICALCVSS 9.1≤ 1.26.42026-08-13
CVE-2026-58433 [CRITICAL] CWE-862 CVE-2026-58433: Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
nvd
CVE-2026-55987P3HIGHCVSS 8.1≤ 1.26.42026-08-13
CVE-2026-55987 [HIGH] CWE-863 CVE-2026-55987: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh toke
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
nvd
CVE-2026-24791P3HIGHCVSS 8.1≥ 1.22.3, ≤ 1.26.12026-08-13
CVE-2026-24791 [HIGH] CWE-863 CVE-2026-24791: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
nvd
CVE-2026-58419P3HIGHCVSS 7.5v1.26.22026-07-03
CVE-2026-58419 [HIGH] CWE-200 CVE-2026-58419: Notification API leaks private issue metadata after access revocation
Notification API leaks private issue metadata after access revocation
nvd
CVE-2026-58443P3CRITICALCVSS 9.1≤ 1.26.42026-08-13
CVE-2026-58443 [CRITICAL] CWE-863 CVE-2026-58443: Public-only repository tokens can update private PR head branches
Public-only repository tokens can update private PR head branches
nvd
CVE-2026-25038P3HIGHCVSS 7.5v1.26.22026-07-03
CVE-2026-25038 [HIGH] CWE-200 CVE-2026-25038: Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
nvd
CVE-2026-24690P3HIGHCVSS 7.5fixed in 1.25.52026-07-03
CVE-2026-24690 [HIGH] CWE-284 CVE-2026-24690: Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull reque
Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
nvd
CVE-2026-27657P3HIGHCVSS 7.5fixed in 1.25.52026-07-03
CVE-2026-27657 [HIGH] CWE-639 CVE-2026-27657: Gitea versions before 1.25.5 allow a user to change another user's primary email address.
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
nvd
CVE-2026-20736P3HIGHCVSS 7.5≤ 1.25.32026-01-22
CVE-2026-20736 [HIGH] CWE-284 CVE-2026-20736: Gitea does not properly verify repository context when deleting attachments. A user who previously u
Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a different repository they can access.
nvd
CVE-2026-58438P3HIGHCVSS 7.5≤ 1.26.42026-08-13
CVE-2026-58438 [HIGH] CWE-862 CVE-2026-58438: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on privat
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
nvd
CVE-2026-58439P3HIGHCVSS 8.1≤ 1.26.42026-08-13
CVE-2026-58439 [HIGH] CWE-284 CVE-2026-58439: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
nvd
CVE-2026-27660P3HIGHCVSS 7.5fixed in 1.25.52026-07-03
CVE-2026-27660 [HIGH] CWE-284 CVE-2026-27660: Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the requ
Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.
nvd
CVE-2026-58417P3HIGHCVSS 7.5≤ 1.26.42026-08-13
CVE-2026-58417 [HIGH] CWE-284 CVE-2026-58417: REST API exposes organization membership of private organizations to public
REST API exposes organization membership of private organizations to public
nvd