Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Gitea Open Source Git Server — Vulnerabilities & Security Advisories 97

All 97 CVE vulnerabilities found in Gitea Open Source Git Server, with AI-generated Chinese analysis, references, and POCs.

This page details known vulnerabilities associated with Gitea, an open-source git server developed by the Gitea community, focusing on weakness types tracked in public databases. It aggregates reported security flaws, including common issues such as cross-site scripting, broken access control, and sensitive data exposure, covering the period from the software's initial releases up to recent updates in 2024. Here, users can track Gitea's security advisories to stay informed about newly disclosed issues, understand the impact and context of specific weakness classes within the application's architecture, and look up the product's comprehensive vulnerability history to assess risk over time. By consolidating this information, the page serves as a central resource for developers, system administrators, and security researchers who need to evaluate the security posture of their Gitea instances. Understanding these vulnerabilities helps teams prioritize patching efforts and implement necessary mitigations to protect their code repositories and associated data. The content is structured to facilitate easy navigation through different versions and severity levels, ensuring that stakeholders can quickly identify relevant risks without sifting through scattered sources. This approach supports proactive security management by providing clear visibility into past incidents and ongoing threats, enabling more informed decision-making regarding system updates and configuration hardening. Ultimately, this aggregation aims to enhance the overall security landscape for Gitea deployments by making critical vulnerability data accessible and actionable for all users.

Vendor: Gitea

CVE IDTitleCVSSSeverityPublished
CVE-2026-58314 Two SSRF findings in Gitea 1.26.2 CWE-918--2026-08-13
CVE-2026-57897 Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs CWE-200--2026-08-13
CVE-2026-57894 Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration CWE-918--2026-08-13
CVE-2026-57886 Cross-repository issue/comment attachment re-linking can expose private attachment content CWE-639--2026-08-13
CVE-2026-56755 Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload CWE-284--2026-08-13
CVE-2026-56750 Gitea Remember-Me Token Theft Not Invalidating Attacker Session CWE-284--2026-08-13
CVE-2026-56657 Gitea SSH Key Parser Denial of Service CWE-284--2026-08-13
CVE-2026-56654 Privilege Escalation via Access Token Scope Escalation in API CWE-284--2026-08-13
CVE-2026-55987 OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) CWE-863--2026-08-13
CVE-2026-55986 Email Management API Bypasses ManageCredentials Feature Restrictions CWE-284--2026-08-13
CVE-2026-56443 Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 CWE-863--2026-08-13
CVE-2026-55984 Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service CWE-284--2026-08-13
CVE-2026-55982 OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes CWE-200--2026-08-13
CVE-2026-54481 Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295) CWE-295--2026-08-13
CVE-2026-50105 RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) CWE-200--2026-08-13
CVE-2026-42931 Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint CWE-770--2026-08-13
CVE-2026-23603 Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim CWE-918--2026-08-13
CVE-2026-58424 Permanent Fork PR Workflow Approval Gate Bypass CWE-285 8.9 High2026-07-03
CVE-2026-58423 LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories CWE-287 7.7 High2026-07-03
CVE-2026-58426 Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write CWE-347 9.6 Critical2026-07-03
CVE-2026-58422 Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts CWE-284--2026-07-03
CVE-2026-58419 Notification API leaks private issue metadata after access revocation CWE-200--2026-07-03
CVE-2026-58421 Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service CWE-284--2026-07-03
CVE-2026-58418 SSRF via HTTP Redirect in Repository Migration CWE-918 6.5 Medium2026-07-03
CVE-2026-28744 Gitea Git smart HTTP bypasses repository token scopes for bearer tokens CWE-863 8.1 High2026-07-03
CVE-2026-28740 Gitea LFS object reuse bypasses Code-unit authorization CWE-639 7.1 High2026-07-03
CVE-2026-28737 Gitea 3D file viewer allows stored XSS through glTF extensionsRequired CWE-79 8.7 High2026-07-03
CVE-2026-28699 Gitea Basic Auth bypasses OAuth2 access token scopes CWE-284 8.1 High2026-07-03
CVE-2026-28705 Gitea repository dumps write release assets using unsafe path names CWE-22--2026-07-03
CVE-2026-27780 Gitea pre-receive hook can miss branch-protection checks after scanner errors CWE-863--2026-07-03

All 97 known CVE vulnerabilities affecting Gitea Open Source Git Server with full Chinese analysis, references, and POCs where available.