cbcvebase.

Gitea Open Source Git Server vulnerabilities

92 known vulnerabilities affecting gitea/gitea_open_source_git_server.

Total CVEs
92
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL21HIGH34MEDIUM32LOW5

Vulnerabilities

Page 4 of 5
CVE-2026-57897P4MEDIUMCVSS 6.5≤ 1.26.42026-08-13
CVE-2026-57897 [MEDIUM] CWE-200 CVE-2026-57897: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
nvd
CVE-2026-58432P3MEDIUMCVSS 5.9≤ 1.26.42026-08-13
CVE-2026-58432 [MEDIUM] CWE-200 CVE-2026-58432: Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
nvd
CVE-2026-58440P4MEDIUMCVSS 6.8≤ 1.26.42026-08-13
CVE-2026-58440 [MEDIUM] CWE-284 CVE-2026-58440: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-tim Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)
nvd
CVE-2026-42931P4MEDIUMCVSS 6.5≤ 1.242026-08-13
CVE-2026-42931 [MEDIUM] CWE-770 CVE-2026-42931: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
nvd
CVE-2026-57886P4MEDIUMCVSS 5.9≤ 1.26.42026-08-13
CVE-2026-57886 [MEDIUM] CWE-639 CVE-2026-57886: Cross-repository issue/comment attachment re-linking can expose private attachment content Cross-repository issue/comment attachment re-linking can expose private attachment content
nvd
CVE-2026-55986P4MEDIUMCVSS 5.4≤ 1.26.42026-08-13
CVE-2026-55986 [MEDIUM] CWE-284 CVE-2026-55986: Email Management API Bypasses ManageCredentials Feature Restrictions Email Management API Bypasses ManageCredentials Feature Restrictions
nvd
CVE-2026-25782P4MEDIUMCVSS 5.3fixed in 1.25.52026-07-03
CVE-2026-25782 [MEDIUM] CWE-639 CVE-2026-25782: Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to t Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.
nvd
CVE-2025-68939P4MEDIUMCVSS 5.3≤ 1.26.42025-12-26
CVE-2025-68939 [MEDIUM] CWE-424 CVE-2025-68939: Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.
nvd
CVE-2025-68941P4MEDIUMCVSS 5.3≤ 1.26.12025-12-26
CVE-2025-68941 [MEDIUM] CWE-863 CVE-2025-68941: Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope l Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.
nvd
CVE-2026-58429P4MEDIUMCVSS 4.9≤ 1.26.42026-08-13
CVE-2026-58429 [MEDIUM] CWE-284 CVE-2026-58429: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
nvd
CVE-2026-28705P4MEDIUMCVSS 5.3fixed in 1.25.52026-07-03
CVE-2026-28705 [MEDIUM] CWE-22 CVE-2026-28705: Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components whe Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.
nvd
CVE-2026-25779P4MEDIUMCVSS 6.1≤ 1.25.42026-07-03
CVE-2026-25779 [MEDIUM] CWE-601 CVE-2026-25779: Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded bac Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect_to values.
nvd
CVE-2026-20909P4MEDIUMCVSS 5.3fixed in 1.25.52026-07-03
CVE-2026-20909 [MEDIUM] CWE-284 CVE-2026-20909: Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries. Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
nvd
CVE-2026-58507P4MEDIUMCVSS 5.3≤ 1.26.42026-08-13
CVE-2026-58507 [MEDIUM] CWE-284 CVE-2026-58507: Private Repository Existence Disclosure via go-get Meta Endpoint Private Repository Existence Disclosure via go-get Meta Endpoint
nvd
CVE-2026-58441P4MEDIUMCVSS 6.3≤ 1.26.42026-08-13
CVE-2026-58441 [MEDIUM] CWE-918 CVE-2026-58441: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
nvd
CVE-2026-27761P4MEDIUMCVSS 4.3≤ 1.26.22026-07-03
CVE-2026-27761 [MEDIUM] CWE-863 CVE-2026-27761: Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.
nvd
CVE-2026-20888P4MEDIUMCVSS 4.3≤ 1.25.32026-01-22
CVE-2026-20888 [MEDIUM] CWE-284 CVE-2026-20888: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interf Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.
nvd
CVE-2026-50105P4MEDIUMCVSS 4.3≤ 1.26.42026-08-13
CVE-2026-50105 [MEDIUM] CWE-200 CVE-2026-50105: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
nvd
CVE-2026-27783P4MEDIUMCVSS 4.3≤ 1.26.12026-07-03
CVE-2026-27783 [MEDIUM] CWE-862 CVE-2026-27783: Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-temp Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.
nvd
CVE-2026-58431P4MEDIUMCVSS 4.3≤ 1.26.42026-08-13
CVE-2026-58431 [MEDIUM] CWE-863 CVE-2026-58431: Public-only API token restriction is not enforced on team API routes Public-only API token restriction is not enforced on team API routes
nvd
Gitea Open Source Git Server vulnerabilities | cvebase