gitea has 61 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 46 in the last 90 days against 9 in the 90 before. The busiest recent month was July 2026 with 45. The median CVSS is 7.1 (high), with 7 rated critical. 2% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-863 (15) and CWE-200 (11). Most affected products: code.gitea.io/gitea (55), Gitea (5), Gitea Open Source Git Server (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 2% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 46 prev 9
Weakness classes
Products
- code.gitea.io/gitea 55
- Gitea 5
- Gitea Open Source Git Server 1
Worst active — by depth score
CVE-2026-60004Critical· 9.8Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.96CVE-2024-6886Critical· 10.0Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.74CVE-2026-58424High· 8.9Gitea: Permanent Fork PR Workflow Approval Gate Bypass61CVE-2026-28699High· 8.1Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication57CVE-2026-58426Critical· 9.6Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write53
gitea vulnerabilities
CVEs affecting gitea, newest first. Open any entry for full detail, references, and exploit status.
61 CVEsRSS
CVE-2026-60004Critical· 9.8CISA KEV0dayPoCGitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
GO-2026-6074NoneGitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
CVE-2026-34966MediumGitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
CVE-2026-59765MediumGitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
CVE-2026-58429Medium· 4.9Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CVE-2026-55984Low· 2.7Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
CVE-2026-58435Medium· 5.4Gitea LFS Deploy-Key Privilege Escalation
Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-55987High· 8.1Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
CVE-2026-58437High· 7.1Gitea: Repository Visibility Manipulation via Git Push Options
Gitea: Repository Visibility Manipulation via Git Push Options
CVE-2026-56657MediumGitea SSH Key Parser Denial of Service
Gitea SSH Key Parser Denial of Service
CVE-2026-58436HighGitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
CVE-2026-58314High· 7.7Gitea: Two SSRF findings
Gitea: Two SSRF findings
CVE-2026-58419High· 7.5Gitea: Notification API leaks private issue metadata after access revocation
Gitea: Notification API leaks private issue metadata after access revocation
CVE-2026-58422HighGitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
CVE-2026-58510Medium· 4.3Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
CVE-2026-57897Medium· 6.5Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
CVE-2026-58511Low· 2.7Gitea: Webhook Authorization Header Returned in Plaintext via API
Gitea: Webhook Authorization Header Returned in Plaintext via API
CVE-2026-59766Medium· 4.3Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`
CVE-2026-58439High· 8.1Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
CVE-2026-56443Medium· 4.3Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
CVE-2026-58428Medium· 6.5Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
CVE-2026-58432Medium· 5.9Gitea: draft release attachment disclosure via missing web authorization
Gitea: draft release attachment disclosure via missing web authorization
CVE-2026-56750CriticalGitea Remember-Me Token Theft Not Invalidating Attacker Session
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
CVE-2026-59763MediumGitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
CVE-2026-58425Medium· 4.3Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
CVE-2026-23603Low· 3.1Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
CVE-2026-57886Medium· 5.9Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
CVE-2026-58507Medium· 5.3Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint
CVE-2026-56755HighGitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
CVE-2026-56654HighGitea: Privilege Escalation via Access Token Scope Escalation in API
Gitea: Privilege Escalation via Access Token Scope Escalation in API