Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Gitea Open Source Git Server — Vulnerabilities & Security Advisories 97

All 97 CVE vulnerabilities found in Gitea Open Source Git Server, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities affecting Gitea, the popular open-source self-hosted Git service. It aggregates security advisories and reported defects to provide a comprehensive view of the product's security posture over time. The collection covers publicly disclosed vulnerabilities, allowing stakeholders to monitor the evolving threat landscape for this specific software stack. Visitors to this page can track vendor advisories as they are issued, offering insight into how quickly the Gitea team responds to critical security findings. Users may also explore the history of a weakness class within the context of Gitea to understand how specific implementation flaws are addressed or if they remain prevalent. By reviewing the product's vulnerability history, developers and system administrators can assess the robustness of the codebase and identify patterns in past security incidents. This resource serves as a factual repository for understanding the security implications of using Gitea in various deployment environments. It does not offer subjective analysis but rather presents the available data regarding reported issues. This approach helps users make informed decisions about risk management, patching strategies, and infrastructure security. Whether you are evaluating Gitea for a new project or maintaining an existing instance, this page provides the necessary context to understand past security events and their impact on the overall stability and safety of the platform.

Vendor: Gitea

CVE ID Title CVSS Severity Published
CVE-2026-24059 Gitea runner registration-token GET endpoint performs a write under a read-only token scope CWE-269 - - 2026-08-13
CVE-2026-24791 Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes CWE-863 - - 2026-08-13
CVE-2026-59765 SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata CWE-918 - - 2026-08-13
CVE-2026-59763 Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads CWE-284 - - 2026-08-13
CVE-2026-58508 Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) CWE-284 - - 2026-08-13
CVE-2026-58511 Webhook Authorization Header Returned in Plaintext via API CWE-200 - - 2026-08-13
CVE-2026-58510 GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private CWE-200 - - 2026-08-13
CVE-2026-58507 Private Repository Existence Disclosure via go-get Meta Endpoint CWE-284 - - 2026-08-13
CVE-2026-58445 Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API CWE-203 - - 2026-08-13
CVE-2026-58444 Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents CWE-863 - - 2026-08-13
CVE-2026-58443 Public-only repository tokens can update private PR head branches CWE-863 - - 2026-08-13
CVE-2026-58441 SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL CWE-918 - - 2026-08-13
CVE-2026-58442 Repository migration SSRF via multi-answer DNS allow-list bypass CWE-200 - - 2026-08-13
CVE-2026-58440 Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`) CWE-284 - - 2026-08-13
CVE-2026-58439 Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag CWE-284 - - 2026-08-13
CVE-2026-58438 Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access CWE-862 - - 2026-08-13
CVE-2026-58437 Repository Visibility Manipulation via Git Push Options CWE-284 - - 2026-08-13
CVE-2026-58436 ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests CWE-407 - - 2026-08-13
CVE-2026-58435 Gitea LFS Deploy-Key Privilege Escalation CWE-266 - - 2026-08-13
CVE-2026-58434 Private Repository Metadata Remains Accessible After Access Revocation CWE-200 - - 2026-08-13
CVE-2026-58433 Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting CWE-862 - - 2026-08-13
CVE-2026-58432 Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea CWE-200 - - 2026-08-13
CVE-2026-58431 Public-only API token restriction is not enforced on team API routes CWE-863 - - 2026-08-13
CVE-2026-58429 Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints CWE-284 - - 2026-08-13
CVE-2026-58428 Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) CWE-424 - - 2026-08-13
CVE-2026-58427 Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 CWE-200 - - 2026-08-13
CVE-2026-58425 OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) CWE-200 - - 2026-08-13
CVE-2026-58416 Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) CWE-280 - - 2026-08-13
CVE-2026-58420 Local File Inclusion via file:// URI in Migration Restore CWE-284 - - 2026-08-13
CVE-2026-58417 REST API exposes organization membership of private organizations to public CWE-284 - - 2026-08-13

All 97 known CVE vulnerabilities affecting Gitea Open Source Git Server with full Chinese analysis, references, and POCs where available.