Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Gitea — Vulnerabilities & Security Advisories 112

Browse all 112 CVE security advisories affecting Gitea. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Gitea is a lightweight, self-hosted Git service designed to provide version control and collaboration features similar to GitHub or GitLab. Its architecture prioritizes ease of deployment and low resource consumption, making it popular among small to medium-sized organizations seeking an alternative to heavier platforms. Historically, security audits have identified several critical vulnerability classes within the codebase, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. These issues often stem from improper input validation or insufficient access controls in specific endpoints. While no massive, widespread breaches have defined its public history, the presence of twenty-two recorded CVEs indicates a pattern of discrete security defects that require diligent patching. The project’s open-source nature allows for community-driven scrutiny, yet the frequency of these findings underscores the necessity for rigorous code review and timely updates to maintain a secure development environment.

CVE ID Title CVSS Severity Published
CVE-2026-28737 Gitea 3D file viewer allows stored XSS through glTF extensionsRequired — Gitea Open Source Git Server CWE-79 8.7 High 2026-07-03
CVE-2026-27779 Gitea forwarded-proto handling allows public URL spoofing — Gitea Open Source Git Server CWE-284 - - 2026-07-03
CVE-2026-27780 Gitea pre-receive hook can miss branch-protection checks after scanner errors — Gitea Open Source Git Server CWE-863 - - 2026-07-03
CVE-2026-27783 Gitea issue-template APIs bypass repository unit authorization — Gitea Open Source Git Server CWE-862 4.3 Medium 2026-07-03
CVE-2026-27761 Gitea repository feeds bypass API token scope enforcement — Gitea Open Source Git Server CWE-863 4.3 Medium 2026-07-03
CVE-2026-27775 Gitea pre-receive hook permission cache allows full repository write access — Gitea Open Source Git Server CWE-863 - - 2026-07-03
CVE-2026-27771 Gitea Composer package source links use insufficient permission checks — Gitea Open Source Git Server CWE-862 - - 2026-07-03
CVE-2026-26307 Gitea git grep search lacks a timeout — Gitea Open Source Git Server CWE-400 - - 2026-07-03
CVE-2026-27660 Gitea draft releases use insufficient permission checks — Gitea Open Source Git Server CWE-284 - - 2026-07-03
CVE-2026-27657 Gitea email settings allow changing another user's primary email address — Gitea Open Source Git Server CWE-639 - - 2026-07-03
CVE-2026-26247 Gitea OAuth2 PKCE S256 challenges are not enforced during token exchange — Gitea Open Source Git Server CWE-284 - - 2026-07-03
CVE-2026-26292 Gitea LFS mirror synchronization bypasses migration HTTP transport restrictions — Gitea Open Source Git Server CWE-284 - - 2026-07-03
CVE-2026-25782 Gitea tracked-time deletion can target entries from another issue — Gitea Open Source Git Server CWE-639 - - 2026-07-03
CVE-2026-26231 Gitea maintainer-edit permissions allow unauthorized commits to readable repositories — Gitea Open Source Git Server CWE-863 8.5 High 2026-07-03
CVE-2026-26232 Gitea OAuth2 authorization codes lack expiry and reuse enforcement — Gitea Open Source Git Server CWE-294 - - 2026-07-03
CVE-2026-25779 Gitea redirect handling permits open redirects through backslash paths — Gitea Open Source Git Server CWE-601 - - 2026-07-03
CVE-2026-25714 Gitea user organization API bypasses public-only token filtering — Gitea Open Source Git Server CWE-862 4.3 Medium 2026-07-03
CVE-2026-25718 Gitea template repository generation mishandles symlinked paths — Gitea Open Source Git Server CWE-59 - - 2026-07-03
CVE-2026-25038 Gitea private organization labels are visible to unauthorized users — Gitea Open Source Git Server CWE-200 - - 2026-07-03
CVE-2026-25712 Gitea organization permission APIs expose private visibility information — Gitea Open Source Git Server CWE-284 - - 2026-07-03
CVE-2026-24690 Gitea pull-request branch updates use insufficient permission checks — Gitea Open Source Git Server CWE-284 - - 2026-07-03
CVE-2026-24451 Gitea fork synchronization can expose private parent repository data — Gitea Open Source Git Server CWE-200 - - 2026-07-03
CVE-2026-22874 Gitea webhook and migration allow-list filtering permits SSRF — Gitea Open Source Git Server CWE-918 9.6 Critical 2026-07-03
CVE-2026-22555 Gitea organization forks can expose organization secrets without create permission — Gitea Open Source Git Server CWE-284 8.1 High 2026-07-03
CVE-2026-22547 Gitea repository creation accepts invalid field values — Gitea Open Source Git Server CWE-20 - - 2026-07-03
CVE-2026-20909 Gitea tracked-time list endpoint has insufficient permission checks — Gitea Open Source Git Server CWE-284 - - 2026-07-03
CVE-2026-20896 Gitea Docker image trusts spoofable reverse-proxy headers by default — Gitea Open Source Git Server CWE-284 9.8 Critical 2026-07-03
CVE-2026-20779 Gitea TOTP single-use enforcement defect allows OTP replay — Gitea Open Source Git Server CWE-294 7.1 High 2026-07-03
CVE-2026-20706 Gitea repository archive downloads bypass token scope checks — Gitea Open Source Git Server CWE-284 - - 2026-07-03
CVE-2026-58053 Gitea act_runner - Container Hardening Bypass via Workflow Container Options — act_runner CWE-269 9.9 Critical 2026-06-28

This page lists every published CVE security advisory associated with Gitea. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.