Gitea Open Source Git Server vulnerabilities
92 known vulnerabilities affecting gitea/gitea_open_source_git_server.
Total CVEs
92
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL21HIGH34MEDIUM32LOW5
Vulnerabilities
Page 4 of 5
CVE-2026-57897P4MEDIUMCVSS 6.5≤ 1.26.42026-08-13
CVE-2026-57897 [MEDIUM] CWE-200 CVE-2026-57897: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
nvd
CVE-2026-58432P3MEDIUMCVSS 5.9≤ 1.26.42026-08-13
CVE-2026-58432 [MEDIUM] CWE-200 CVE-2026-58432: Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
nvd
CVE-2026-58440P4MEDIUMCVSS 6.8≤ 1.26.42026-08-13
CVE-2026-58440 [MEDIUM] CWE-284 CVE-2026-58440: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-tim
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)
nvd
CVE-2026-42931P4MEDIUMCVSS 6.5≤ 1.242026-08-13
CVE-2026-42931 [MEDIUM] CWE-770 CVE-2026-42931: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
nvd
CVE-2026-57886P4MEDIUMCVSS 5.9≤ 1.26.42026-08-13
CVE-2026-57886 [MEDIUM] CWE-639 CVE-2026-57886: Cross-repository issue/comment attachment re-linking can expose private attachment content
Cross-repository issue/comment attachment re-linking can expose private attachment content
nvd
CVE-2026-55986P4MEDIUMCVSS 5.4≤ 1.26.42026-08-13
CVE-2026-55986 [MEDIUM] CWE-284 CVE-2026-55986: Email Management API Bypasses ManageCredentials Feature Restrictions
Email Management API Bypasses ManageCredentials Feature Restrictions
nvd
CVE-2026-25782P4MEDIUMCVSS 5.3fixed in 1.25.52026-07-03
CVE-2026-25782 [MEDIUM] CWE-639 CVE-2026-25782: Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to t
Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.
nvd
CVE-2025-68939P4MEDIUMCVSS 5.3≤ 1.26.42025-12-26
CVE-2025-68939 [MEDIUM] CWE-424 CVE-2025-68939: Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an
Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.
nvd
CVE-2025-68941P4MEDIUMCVSS 5.3≤ 1.26.12025-12-26
CVE-2025-68941 [MEDIUM] CWE-863 CVE-2025-68941: Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope l
Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.
nvd
CVE-2026-58429P4MEDIUMCVSS 4.9≤ 1.26.42026-08-13
CVE-2026-58429 [MEDIUM] CWE-284 CVE-2026-58429: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
nvd
CVE-2026-28705P4MEDIUMCVSS 5.3fixed in 1.25.52026-07-03
CVE-2026-28705 [MEDIUM] CWE-22 CVE-2026-28705: Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components whe
Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.
nvd
CVE-2026-25779P4MEDIUMCVSS 6.1≤ 1.25.42026-07-03
CVE-2026-25779 [MEDIUM] CWE-601 CVE-2026-25779: Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded bac
Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect_to values.
nvd
CVE-2026-20909P4MEDIUMCVSS 5.3fixed in 1.25.52026-07-03
CVE-2026-20909 [MEDIUM] CWE-284 CVE-2026-20909: Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
nvd
CVE-2026-58507P4MEDIUMCVSS 5.3≤ 1.26.42026-08-13
CVE-2026-58507 [MEDIUM] CWE-284 CVE-2026-58507: Private Repository Existence Disclosure via go-get Meta Endpoint
Private Repository Existence Disclosure via go-get Meta Endpoint
nvd
CVE-2026-58441P4MEDIUMCVSS 6.3≤ 1.26.42026-08-13
CVE-2026-58441 [MEDIUM] CWE-918 CVE-2026-58441: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
nvd
CVE-2026-27761P4MEDIUMCVSS 4.3≤ 1.26.22026-07-03
CVE-2026-27761 [MEDIUM] CWE-863 CVE-2026-27761: Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API
Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.
nvd
CVE-2026-20888P4MEDIUMCVSS 4.3≤ 1.25.32026-01-22
CVE-2026-20888 [MEDIUM] CWE-284 CVE-2026-20888: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interf
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.
nvd
CVE-2026-50105P4MEDIUMCVSS 4.3≤ 1.26.42026-08-13
CVE-2026-50105 [MEDIUM] CWE-200 CVE-2026-50105: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
nvd
CVE-2026-27783P4MEDIUMCVSS 4.3≤ 1.26.12026-07-03
CVE-2026-27783 [MEDIUM] CWE-862 CVE-2026-27783: Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-temp
Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.
nvd
CVE-2026-58431P4MEDIUMCVSS 4.3≤ 1.26.42026-08-13
CVE-2026-58431 [MEDIUM] CWE-863 CVE-2026-58431: Public-only API token restriction is not enforced on team API routes
Public-only API token restriction is not enforced on team API routes
nvd