Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Gitea Open Source Git Server — Vulnerabilities & Security Advisories 97

All 97 CVE vulnerabilities found in Gitea Open Source Git Server, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities affecting Gitea, an open source Git server developed by the Gitea organization. It collects security flaws including remote code execution, privilege escalation, and cross-site scripting issues reported across its entire release history. Readers can use this resource to track the vendor’s security advisories, analyze recurring weakness patterns, and review the product’s vulnerability history to assess risk trends. The collection spans all publicly disclosed CVEs from initial releases through current versions, providing a centralized view of past and present security exposure. No specific CVE identifiers are listed in this introduction; instead, focus remains on the aggregation of weakness types over time. Users should leverage this page to monitor new advisories, understand how different vulnerability classes evolve within the codebase, and plan mitigations based on historical frequency and severity of reported defects.

Vendor: Gitea

CVE ID Title CVSS Severity Published
CVE-2026-58314 Two SSRF findings in Gitea 1.26.2 CWE-918 - - 2026-08-13
CVE-2026-57897 Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs CWE-200 - - 2026-08-13
CVE-2026-57894 Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration CWE-918 - - 2026-08-13
CVE-2026-57886 Cross-repository issue/comment attachment re-linking can expose private attachment content CWE-639 - - 2026-08-13
CVE-2026-56755 Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload CWE-284 - - 2026-08-13
CVE-2026-56750 Gitea Remember-Me Token Theft Not Invalidating Attacker Session CWE-284 - - 2026-08-13
CVE-2026-56657 Gitea SSH Key Parser Denial of Service CWE-284 - - 2026-08-13
CVE-2026-56654 Privilege Escalation via Access Token Scope Escalation in API CWE-284 - - 2026-08-13
CVE-2026-55987 OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) CWE-863 - - 2026-08-13
CVE-2026-55986 Email Management API Bypasses ManageCredentials Feature Restrictions CWE-284 - - 2026-08-13
CVE-2026-56443 Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 CWE-863 - - 2026-08-13
CVE-2026-55984 Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service CWE-284 - - 2026-08-13
CVE-2026-55982 OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes CWE-200 - - 2026-08-13
CVE-2026-54481 Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295) CWE-295 - - 2026-08-13
CVE-2026-50105 RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) CWE-200 - - 2026-08-13
CVE-2026-42931 Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint CWE-770 - - 2026-08-13
CVE-2026-23603 Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim CWE-918 - - 2026-08-13
CVE-2026-58424 Permanent Fork PR Workflow Approval Gate Bypass CWE-285 8.9 High 2026-07-03
CVE-2026-58423 LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories CWE-287 7.7 High 2026-07-03
CVE-2026-58426 Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write CWE-347 9.6 Critical 2026-07-03
CVE-2026-58422 Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts CWE-284 - - 2026-07-03
CVE-2026-58419 Notification API leaks private issue metadata after access revocation CWE-200 - - 2026-07-03
CVE-2026-58421 Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service CWE-284 - - 2026-07-03
CVE-2026-58418 SSRF via HTTP Redirect in Repository Migration CWE-918 6.5 Medium 2026-07-03
CVE-2026-28744 Gitea Git smart HTTP bypasses repository token scopes for bearer tokens CWE-863 8.1 High 2026-07-03
CVE-2026-28740 Gitea LFS object reuse bypasses Code-unit authorization CWE-639 7.1 High 2026-07-03
CVE-2026-28737 Gitea 3D file viewer allows stored XSS through glTF extensionsRequired CWE-79 8.7 High 2026-07-03
CVE-2026-28699 Gitea Basic Auth bypasses OAuth2 access token scopes CWE-284 8.1 High 2026-07-03
CVE-2026-28705 Gitea repository dumps write release assets using unsafe path names CWE-22 - - 2026-07-03
CVE-2026-27780 Gitea pre-receive hook can miss branch-protection checks after scanner errors CWE-863 - - 2026-07-03

All 97 known CVE vulnerabilities affecting Gitea Open Source Git Server with full Chinese analysis, references, and POCs where available.