Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Gitea — Vulnerabilities & Security Advisories 112

Browse all 112 CVE security advisories affecting Gitea. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Gitea is a lightweight, self-hosted Git service designed to provide version control and collaboration features similar to GitHub or GitLab. Its architecture prioritizes ease of deployment and low resource consumption, making it popular among small to medium-sized organizations seeking an alternative to heavier platforms. Historically, security audits have identified several critical vulnerability classes within the codebase, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. These issues often stem from improper input validation or insufficient access controls in specific endpoints. While no massive, widespread breaches have defined its public history, the presence of twenty-two recorded CVEs indicates a pattern of discrete security defects that require diligent patching. The project’s open-source nature allows for community-driven scrutiny, yet the frequency of these findings underscores the necessity for rigorous code review and timely updates to maintain a secure development environment.

CVE ID Title CVSS Severity Published
CVE-2026-58420 Local File Inclusion via file:// URI in Migration Restore — Gitea Open Source Git Server CWE-284 - - 2026-08-13
CVE-2026-57897 Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs — Gitea Open Source Git Server CWE-200 - - 2026-08-13
CVE-2026-58314 Two SSRF findings in Gitea 1.26.2 — Gitea Open Source Git Server CWE-918 - - 2026-08-13
CVE-2026-57886 Cross-repository issue/comment attachment re-linking can expose private attachment content — Gitea Open Source Git Server CWE-639 - - 2026-08-13
CVE-2026-57894 Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration — Gitea Open Source Git Server CWE-918 - - 2026-08-13
CVE-2026-56750 Gitea Remember-Me Token Theft Not Invalidating Attacker Session — Gitea Open Source Git Server CWE-284 - - 2026-08-13
CVE-2026-56755 Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload — Gitea Open Source Git Server CWE-284 - - 2026-08-13
CVE-2026-56654 Privilege Escalation via Access Token Scope Escalation in API — Gitea Open Source Git Server CWE-284 - - 2026-08-13
CVE-2026-56657 Gitea SSH Key Parser Denial of Service — Gitea Open Source Git Server CWE-284 - - 2026-08-13
CVE-2026-55987 OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) — Gitea Open Source Git Server CWE-863 - - 2026-08-13
CVE-2026-56443 Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 — Gitea Open Source Git Server CWE-863 - - 2026-08-13
CVE-2026-55986 Email Management API Bypasses ManageCredentials Feature Restrictions — Gitea Open Source Git Server CWE-284 - - 2026-08-13
CVE-2026-55984 Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service — Gitea Open Source Git Server CWE-284 - - 2026-08-13
CVE-2026-54481 Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295) — Gitea Open Source Git Server CWE-295 - - 2026-08-13
CVE-2026-55982 OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes — Gitea Open Source Git Server CWE-200 - - 2026-08-13
CVE-2026-42931 Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint — Gitea Open Source Git Server CWE-770 - - 2026-08-13
CVE-2026-50105 RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) — Gitea Open Source Git Server CWE-200 - - 2026-08-13
CVE-2026-23603 Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim — Gitea Open Source Git Server CWE-918 - - 2026-08-13
CVE-2026-34966 Gitea prior to 1.27.0 SSRF via Migration URI Fetch Bypass — Gitea CWE-918 7.6 High 2026-08-05
CVE-2026-58424 Permanent Fork PR Workflow Approval Gate Bypass — Gitea Open Source Git Server CWE-285 8.9 High 2026-07-03
CVE-2026-58423 LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories — Gitea Open Source Git Server CWE-287 7.7 High 2026-07-03
CVE-2026-58426 Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write — Gitea Open Source Git Server CWE-347 9.6 Critical 2026-07-03
CVE-2026-58421 Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service — Gitea Open Source Git Server CWE-284 - - 2026-07-03
CVE-2026-58419 Notification API leaks private issue metadata after access revocation — Gitea Open Source Git Server CWE-200 - - 2026-07-03
CVE-2026-58422 Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts — Gitea Open Source Git Server CWE-284 - - 2026-07-03
CVE-2026-58418 SSRF via HTTP Redirect in Repository Migration — Gitea Open Source Git Server CWE-918 6.5 Medium 2026-07-03
CVE-2026-28744 Gitea Git smart HTTP bypasses repository token scopes for bearer tokens — Gitea Open Source Git Server CWE-863 8.1 High 2026-07-03
CVE-2026-28740 Gitea LFS object reuse bypasses Code-unit authorization — Gitea Open Source Git Server CWE-639 7.1 High 2026-07-03
CVE-2026-28699 Gitea Basic Auth bypasses OAuth2 access token scopes — Gitea Open Source Git Server CWE-284 8.1 High 2026-07-03
CVE-2026-28705 Gitea repository dumps write release assets using unsafe path names — Gitea Open Source Git Server CWE-22 - - 2026-07-03

This page lists every published CVE security advisory associated with Gitea. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.