Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Gitea — Vulnerabilities & Security Advisories 112

Browse all 112 CVE security advisories affecting Gitea. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Gitea is a lightweight, self-hosted Git service designed to provide version control and collaboration features similar to GitHub or GitLab. Its architecture prioritizes ease of deployment and low resource consumption, making it popular among small to medium-sized organizations seeking an alternative to heavier platforms. Historically, security audits have identified several critical vulnerability classes within the codebase, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. These issues often stem from improper input validation or insufficient access controls in specific endpoints. While no massive, widespread breaches have defined its public history, the presence of twenty-two recorded CVEs indicates a pattern of discrete security defects that require diligent patching. The project’s open-source nature allows for community-driven scrutiny, yet the frequency of these findings underscores the necessity for rigorous code review and timely updates to maintain a secure development environment.

CVE ID Title CVSS Severity Published
CVE-2026-60004 Gitea 代码注入漏洞 — Gitea CWE-94 9.8 Critical 2026-08-26
CVE-2026-24059 Gitea runner registration-token GET endpoint performs a write under a read-only token scope — Gitea Open Source Git Server CWE-269 - - 2026-08-13
CVE-2026-24791 Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes — Gitea Open Source Git Server CWE-863 - - 2026-08-13
CVE-2026-59765 SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata — Gitea Open Source Git Server CWE-918 - - 2026-08-13
CVE-2026-59763 Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads — Gitea Open Source Git Server CWE-284 - - 2026-08-13
CVE-2026-58508 Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) — Gitea Open Source Git Server CWE-284 - - 2026-08-13
CVE-2026-58511 Webhook Authorization Header Returned in Plaintext via API — Gitea Open Source Git Server CWE-200 - - 2026-08-13
CVE-2026-58510 GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private — Gitea Open Source Git Server CWE-200 - - 2026-08-13
CVE-2026-58507 Private Repository Existence Disclosure via go-get Meta Endpoint — Gitea Open Source Git Server CWE-284 - - 2026-08-13
CVE-2026-58445 Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API — Gitea Open Source Git Server CWE-203 - - 2026-08-13
CVE-2026-58444 Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents — Gitea Open Source Git Server CWE-863 - - 2026-08-13
CVE-2026-58443 Public-only repository tokens can update private PR head branches — Gitea Open Source Git Server CWE-863 - - 2026-08-13
CVE-2026-58442 Repository migration SSRF via multi-answer DNS allow-list bypass — Gitea Open Source Git Server CWE-200 - - 2026-08-13
CVE-2026-58441 SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL — Gitea Open Source Git Server CWE-918 - - 2026-08-13
CVE-2026-58440 Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`) — Gitea Open Source Git Server CWE-284 - - 2026-08-13
CVE-2026-58439 Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag — Gitea Open Source Git Server CWE-284 - - 2026-08-13
CVE-2026-58438 Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access — Gitea Open Source Git Server CWE-862 - - 2026-08-13
CVE-2026-58437 Repository Visibility Manipulation via Git Push Options — Gitea Open Source Git Server CWE-284 - - 2026-08-13
CVE-2026-58436 ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests — Gitea Open Source Git Server CWE-407 - - 2026-08-13
CVE-2026-58435 Gitea LFS Deploy-Key Privilege Escalation — Gitea Open Source Git Server CWE-266 - - 2026-08-13
CVE-2026-58433 Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting — Gitea Open Source Git Server CWE-862 - - 2026-08-13
CVE-2026-58434 Private Repository Metadata Remains Accessible After Access Revocation — Gitea Open Source Git Server CWE-200 - - 2026-08-13
CVE-2026-58431 Public-only API token restriction is not enforced on team API routes — Gitea Open Source Git Server CWE-863 - - 2026-08-13
CVE-2026-58432 Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea — Gitea Open Source Git Server CWE-200 - - 2026-08-13
CVE-2026-58428 Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) — Gitea Open Source Git Server CWE-424 - - 2026-08-13
CVE-2026-58429 Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints — Gitea Open Source Git Server CWE-284 - - 2026-08-13
CVE-2026-58427 Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 — Gitea Open Source Git Server CWE-200 - - 2026-08-13
CVE-2026-58425 OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) — Gitea Open Source Git Server CWE-200 - - 2026-08-13
CVE-2026-58420 Local File Inclusion via file:// URI in Migration Restore — Gitea Open Source Git Server CWE-284 - - 2026-08-13
CVE-2026-58417 REST API exposes organization membership of private organizations to public — Gitea Open Source Git Server CWE-284 - - 2026-08-13

This page lists every published CVE security advisory associated with Gitea. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.