Gitea Open Source Git Server vulnerabilities
92 known vulnerabilities affecting gitea/gitea_open_source_git_server.
Total CVEs
92
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL21HIGH34MEDIUM32LOW5
Vulnerabilities
Page 5 of 5
CVE-2026-56755P4MEDIUMCVSS 6.2≤ 1.26.42026-08-13
CVE-2026-56755 [MEDIUM] CWE-284 CVE-2026-56755: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
nvd
CVE-2026-58420P4MEDIUMCVSS 4.4≤ 1.26.42026-08-13
CVE-2026-58420 [MEDIUM] CWE-284 CVE-2026-58420: Local File Inclusion via file:// URI in Migration Restore
Local File Inclusion via file:// URI in Migration Restore
nvd
CVE-2026-25714P4MEDIUMCVSS 4.3≤ 1.26.42026-07-03
CVE-2026-25714 [MEDIUM] CWE-862 CVE-2026-25714: Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to t
Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.
nvd
CVE-2026-58444P4MEDIUMCVSS 4.3fixed in 1.27.02026-08-13
CVE-2026-58444 [MEDIUM] CWE-863 CVE-2026-58444: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) d
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
nvd
CVE-2026-58425P4MEDIUMCVSS 4.3≤ 1.26.42026-08-13
CVE-2026-58425 [MEDIUM] CWE-200 CVE-2026-58425: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 vio
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
nvd
CVE-2026-58510P4MEDIUMCVSS 4.3≤ 1.26.42026-08-13
CVE-2026-58510 [MEDIUM] CWE-200 CVE-2026-58510: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
nvd
CVE-2026-59763P4MEDIUMCVSS 4.3≤ 1.26.42026-08-13
CVE-2026-59763 [MEDIUM] CWE-284 CVE-2026-59763: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
nvd
CVE-2026-0798P4LOWCVSS 3.5≤ 1.25.32026-01-22
CVE-2026-0798 [LOW] CWE-284 CVE-2026-0798: Gitea may send release notification emails for private repositories to users whose access has been r
Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content.
nvd
CVE-2026-23603P4LOWCVSS 3.1≤ 1.26.42026-08-13
CVE-2026-23603 [LOW] CWE-918 CVE-2026-23603: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
nvd
CVE-2026-58511P4LOWCVSS 2.7≤ 1.26.42026-08-13
CVE-2026-58511 [LOW] CWE-200 CVE-2026-58511: Webhook Authorization Header Returned in Plaintext via API
Webhook Authorization Header Returned in Plaintext via API
nvd
CVE-2026-58445P4LOWCVSS 2.7≤ 1.26.42026-08-13
CVE-2026-58445 [LOW] CWE-203 CVE-2026-58445: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
nvd
CVE-2026-55984P4LOWCVSS 2.7≤ 1.26.42026-08-13
CVE-2026-55984 [LOW] CWE-284 CVE-2026-55984: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
nvd
← Previous5 / 5