VulnSea

Gitea has 61 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 46 in the last 90 days against 9 in the 90 before. The busiest recent month was July 2026 with 44. The median CVSS is 7.3 (high), with 7 rated critical. 2% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-863 (15) and CWE-200 (11). Most affected products: code.gitea.io/gitea (55), Gitea (5), Gitea Open Source Git Server (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
2% vs 1% corpus
Median CVSS
7.3
Publish → KEV
—
Last 90 days
46 prev 9

Products

  • code.gitea.io/gitea 55
  • Gitea 5
  • Gitea Open Source Git Server 1
61
Total CVEs
7
Critical
1
CISA KEV
1
Exploited

Gitea vulnerabilities

CVEs affecting Gitea, newest first. Open any entry for full detail, references, and exploit status.

61 CVEsRSS

GHSA-rjvx-x5h2-6px5Medium
2mo ago

Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions

Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions

▾ Sunlitgitea · code.gitea.io/giteavia GHSA
CVE-2026-58418Medium· 6.5
2mo ago

Gitea: SSRF via HTTP Redirect in Repository Migration

Gitea: SSRF via HTTP Redirect in Repository Migration

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.41%via GHSA
CVE-2026-58421High· 7.5
2mo ago

Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.58%via GHSA
CVE-2026-58423High· 7.7
2mo ago

Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.54%via GHSA
CVE-2026-58424High· 8.9PoC
2mo ago

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

▾ Midnightgitea · code.gitea.io/giteaEPSS 0.37%via GHSA
CVE-2026-58426Critical· 9.6
2mo ago

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

▾ Midnightgitea · code.gitea.io/giteaEPSS 0.30%via GHSA
CVE-2026-58441Medium· 6.3
2mo ago

Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL

Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.17%via GHSA
CVE-2026-58442Medium· 6.5
2mo ago

Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass

Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.43%via GHSA
CVE-2026-58444Medium· 4.3
2mo ago

Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.36%via GHSA
CVE-2026-58445Low· 2.7
2mo ago

Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.37%via GHSA
CVE-2026-42931Medium· 6.5
2mo ago

Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.53%via GHSA
CVE-2026-50105Medium· 4.3
2mo ago

Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.36%via GHSA
CVE-2026-54481High· 7.5
2mo ago

Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override

Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.30%via GHSA
CVE-2026-58434Low
2mo ago

Gitea: Private Repository Metadata Remains Accessible After Access Revocation

Gitea: Private Repository Metadata Remains Accessible After Access Revocation

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.47%via GHSA
CVE-2026-55982Medium
2mo ago

Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.51%via GHSA
CVE-2026-57894High· 8.5
2mo ago

Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.36%via GHSA
CVE-2026-22555High· 8.1
3mo ago

Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration

Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.43%via GHSA
CVE-2026-24791High· 8.1
3mo ago

Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.45%via GHSA
CVE-2026-28737High· 8.7
3mo ago

Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer

Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.43%via GHSA
CVE-2026-28744High· 8.1
3mo ago

Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens

Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.45%via GHSA
CVE-2026-28699High· 8.1PoC
3mo ago

Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication

Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication

▾ Midnightgitea · code.gitea.io/giteaEPSS 0.55%via GHSA
CVE-2026-26231High· 8.5
3mo ago

Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo

Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.35%via GHSA
CVE-2026-25714Medium· 4.3
3mo ago

Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw

Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.34%via GHSA
CVE-2026-27783Medium· 4.3
3mo ago

Gitea: Missing repository-unit authorization on issue-template API endpoints

Gitea: Missing repository-unit authorization on issue-template API endpoints

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.34%via GHSA
CVE-2026-20706Medium
3mo ago

Gitea: Token scope bypass on web archive download endpoint

Gitea: Token scope bypass on web archive download endpoint

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.56%via GHSA
CVE-2026-20736High· 7.5
8mo ago

Gitea does not properly verify repository context when deleting attachments

Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a dif…

▾ Twilightgitea · giteaEPSS 0.44%via NVD
CVE-2026-20912Critical· 9.1
8mo ago

Gitea does not properly validate repository ownership when linking attachments to releases

Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to…

▾ Midnightgitea · giteaEPSS 0.46%via NVD
CVE-2026-20897Critical· 9.1
8mo ago

Gitea does not properly validate repository ownership when deleting Git LFS locks

Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.

▾ Midnightgitea · giteaEPSS 0.46%via NVD
CVE-2026-20750Critical· 9.1
8mo ago

Gitea does not properly validate project ownership in organization project operations

Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization.

▾ Midnightgitea · giteaEPSS 0.44%via NVD
CVE-2025-68939High· 8.2
9mo ago

Gitea allows attackers to add attachments with forbidden file extensions

Gitea allows attackers to add attachments with forbidden file extensions

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.33%via OSV
Gitea vulnerabilities (CVEs) — page 2 · VulnSea