Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Gitea Open Source Git Server — Vulnerabilities & Security Advisories 97

All 97 CVE vulnerabilities found in Gitea Open Source Git Server, with AI-generated Chinese analysis, references, and POCs.

This page details known vulnerabilities associated with Gitea, an open-source git server developed by the Gitea community, focusing on weakness types tracked in public databases. It aggregates reported security flaws, including common issues such as cross-site scripting, broken access control, and sensitive data exposure, covering the period from the software's initial releases up to recent updates in 2024. Here, users can track Gitea's security advisories to stay informed about newly disclosed issues, understand the impact and context of specific weakness classes within the application's architecture, and look up the product's comprehensive vulnerability history to assess risk over time. By consolidating this information, the page serves as a central resource for developers, system administrators, and security researchers who need to evaluate the security posture of their Gitea instances. Understanding these vulnerabilities helps teams prioritize patching efforts and implement necessary mitigations to protect their code repositories and associated data. The content is structured to facilitate easy navigation through different versions and severity levels, ensuring that stakeholders can quickly identify relevant risks without sifting through scattered sources. This approach supports proactive security management by providing clear visibility into past incidents and ongoing threats, enabling more informed decision-making regarding system updates and configuration hardening. Ultimately, this aggregation aims to enhance the overall security landscape for Gitea deployments by making critical vulnerability data accessible and actionable for all users.

Vendor: Gitea

CVE IDTitleCVSSSeverityPublished
CVE-2026-27779 Gitea forwarded-proto handling allows public URL spoofing CWE-284--2026-07-03
CVE-2026-27783 Gitea issue-template APIs bypass repository unit authorization CWE-862 4.3 Medium2026-07-03
CVE-2026-27761 Gitea repository feeds bypass API token scope enforcement CWE-863 4.3 Medium2026-07-03
CVE-2026-27771 Gitea Composer package source links use insufficient permission checks CWE-862--2026-07-03
CVE-2026-27775 Gitea pre-receive hook permission cache allows full repository write access CWE-863--2026-07-03
CVE-2026-27657 Gitea email settings allow changing another user's primary email address CWE-639--2026-07-03
CVE-2026-26307 Gitea git grep search lacks a timeout CWE-400--2026-07-03
CVE-2026-27660 Gitea draft releases use insufficient permission checks CWE-284--2026-07-03
CVE-2026-26247 Gitea OAuth2 PKCE S256 challenges are not enforced during token exchange CWE-284--2026-07-03
CVE-2026-26292 Gitea LFS mirror synchronization bypasses migration HTTP transport restrictions CWE-284--2026-07-03
CVE-2026-25782 Gitea tracked-time deletion can target entries from another issue CWE-639--2026-07-03
CVE-2026-26231 Gitea maintainer-edit permissions allow unauthorized commits to readable repositories CWE-863 8.5 High2026-07-03
CVE-2026-26232 Gitea OAuth2 authorization codes lack expiry and reuse enforcement CWE-294--2026-07-03
CVE-2026-25779 Gitea redirect handling permits open redirects through backslash paths CWE-601--2026-07-03
CVE-2026-25714 Gitea user organization API bypasses public-only token filtering CWE-862 4.3 Medium2026-07-03
CVE-2026-25718 Gitea template repository generation mishandles symlinked paths CWE-59--2026-07-03
CVE-2026-25712 Gitea organization permission APIs expose private visibility information CWE-284--2026-07-03
CVE-2026-24690 Gitea pull-request branch updates use insufficient permission checks CWE-284--2026-07-03
CVE-2026-25038 Gitea private organization labels are visible to unauthorized users CWE-200--2026-07-03
CVE-2026-22874 Gitea webhook and migration allow-list filtering permits SSRF CWE-918 9.6 Critical2026-07-03
CVE-2026-24451 Gitea fork synchronization can expose private parent repository data CWE-200--2026-07-03
CVE-2026-22555 Gitea organization forks can expose organization secrets without create permission CWE-284 8.1 High2026-07-03
CVE-2026-22547 Gitea repository creation accepts invalid field values CWE-20--2026-07-03
CVE-2026-20909 Gitea tracked-time list endpoint has insufficient permission checks CWE-284--2026-07-03
CVE-2026-20896 Gitea Docker image trusts spoofable reverse-proxy headers by default CWE-284 9.8 Critical2026-07-03
CVE-2026-20779 Gitea TOTP single-use enforcement defect allows OTP replay CWE-294 7.1 High2026-07-03
CVE-2026-20706 Gitea repository archive downloads bypass token scope checks CWE-284--2026-07-03
CVE-2026-20897 Gitea Git LFS Lock Deletion Broken Access Control (Cross-Repo IDOR) CWE-284 6.5AIMediumAI2026-01-22
CVE-2026-20904 Gitea: Broken access control in OpenID visibility toggle enables cross-user visibility changes CWE-284 4.3AIMediumAI2026-01-22
CVE-2026-20912 Gitea: Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attachment Disclosure CWE-284 7.5AIHighAI2026-01-22

All 97 known CVE vulnerabilities affecting Gitea Open Source Git Server with full Chinese analysis, references, and POCs where available.