gitea.dev vulnerabilities
CVEs whose affected-version data names the gitea.dev package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
7 CVEsRSS
CVE-2026-58420MediumGitea: Local File Inclusion via file:// URI in Migration Restore
Gitea: Local File Inclusion via file:// URI in Migration Restore
CVE-2026-58427MediumGitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
CVE-2026-58431Medium· 4.3Gitea: Public-only API token restriction is not enforced on team API routes
Gitea: Public-only API token restriction is not enforced on team API routes
CVE-2026-58440Medium· 6.8Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content
CVE-2026-58438LowGitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
CVE-2026-58416Medium· 6.3Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
CVE-2026-58417MediumGitea: REST API exposes organization membership of private organizations to public
Gitea: REST API exposes organization membership of private organizations to public