Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Gitea Open Source Git Server — Vulnerabilities & Security Advisories 97

All 97 CVE vulnerabilities found in Gitea Open Source Git Server, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities affecting Gitea, an open source Git server developed by the Gitea organization. It collects security flaws including remote code execution, privilege escalation, and cross-site scripting issues reported across its entire release history. Readers can use this resource to track the vendor’s security advisories, analyze recurring weakness patterns, and review the product’s vulnerability history to assess risk trends. The collection spans all publicly disclosed CVEs from initial releases through current versions, providing a centralized view of past and present security exposure. No specific CVE identifiers are listed in this introduction; instead, focus remains on the aggregation of weakness types over time. Users should leverage this page to monitor new advisories, understand how different vulnerability classes evolve within the codebase, and plan mitigations based on historical frequency and severity of reported defects.

Vendor: Gitea

CVE ID Title CVSS Severity Published
CVE-2026-27779 Gitea forwarded-proto handling allows public URL spoofing CWE-284 - - 2026-07-03
CVE-2026-27783 Gitea issue-template APIs bypass repository unit authorization CWE-862 4.3 Medium 2026-07-03
CVE-2026-27761 Gitea repository feeds bypass API token scope enforcement CWE-863 4.3 Medium 2026-07-03
CVE-2026-27771 Gitea Composer package source links use insufficient permission checks CWE-862 - - 2026-07-03
CVE-2026-27775 Gitea pre-receive hook permission cache allows full repository write access CWE-863 - - 2026-07-03
CVE-2026-27657 Gitea email settings allow changing another user's primary email address CWE-639 - - 2026-07-03
CVE-2026-26307 Gitea git grep search lacks a timeout CWE-400 - - 2026-07-03
CVE-2026-27660 Gitea draft releases use insufficient permission checks CWE-284 - - 2026-07-03
CVE-2026-26247 Gitea OAuth2 PKCE S256 challenges are not enforced during token exchange CWE-284 - - 2026-07-03
CVE-2026-26292 Gitea LFS mirror synchronization bypasses migration HTTP transport restrictions CWE-284 - - 2026-07-03
CVE-2026-25782 Gitea tracked-time deletion can target entries from another issue CWE-639 - - 2026-07-03
CVE-2026-26231 Gitea maintainer-edit permissions allow unauthorized commits to readable repositories CWE-863 8.5 High 2026-07-03
CVE-2026-26232 Gitea OAuth2 authorization codes lack expiry and reuse enforcement CWE-294 - - 2026-07-03
CVE-2026-25779 Gitea redirect handling permits open redirects through backslash paths CWE-601 - - 2026-07-03
CVE-2026-25714 Gitea user organization API bypasses public-only token filtering CWE-862 4.3 Medium 2026-07-03
CVE-2026-25718 Gitea template repository generation mishandles symlinked paths CWE-59 - - 2026-07-03
CVE-2026-25712 Gitea organization permission APIs expose private visibility information CWE-284 - - 2026-07-03
CVE-2026-24690 Gitea pull-request branch updates use insufficient permission checks CWE-284 - - 2026-07-03
CVE-2026-25038 Gitea private organization labels are visible to unauthorized users CWE-200 - - 2026-07-03
CVE-2026-22874 Gitea webhook and migration allow-list filtering permits SSRF CWE-918 9.6 Critical 2026-07-03
CVE-2026-24451 Gitea fork synchronization can expose private parent repository data CWE-200 - - 2026-07-03
CVE-2026-22555 Gitea organization forks can expose organization secrets without create permission CWE-284 8.1 High 2026-07-03
CVE-2026-22547 Gitea repository creation accepts invalid field values CWE-20 - - 2026-07-03
CVE-2026-20909 Gitea tracked-time list endpoint has insufficient permission checks CWE-284 - - 2026-07-03
CVE-2026-20896 Gitea Docker image trusts spoofable reverse-proxy headers by default CWE-284 9.8 Critical 2026-07-03
CVE-2026-20779 Gitea TOTP single-use enforcement defect allows OTP replay CWE-294 7.1 High 2026-07-03
CVE-2026-20706 Gitea repository archive downloads bypass token scope checks CWE-284 - - 2026-07-03
CVE-2026-20897 Gitea Git LFS Lock Deletion Broken Access Control (Cross-Repo IDOR) CWE-284 6.5AI Medium AI 2026-01-22
CVE-2026-20904 Gitea: Broken access control in OpenID visibility toggle enables cross-user visibility changes CWE-284 4.3AI Medium AI 2026-01-22
CVE-2026-20912 Gitea: Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attachment Disclosure CWE-284 7.5AI High AI 2026-01-22

All 97 known CVE vulnerabilities affecting Gitea Open Source Git Server with full Chinese analysis, references, and POCs where available.