VulnSea

gitea has 61 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 46 in the last 90 days against 9 in the 90 before. The busiest recent month was July 2026 with 45. The median CVSS is 7.1 (high), with 7 rated critical. 2% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-863 (15) and CWE-200 (11). Most affected products: code.gitea.io/gitea (55), Gitea (5), Gitea Open Source Git Server (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
2% vs 1% corpus
Median CVSS
7.1
Publish → KEV
Last 90 days
46 prev 9

Products

  • code.gitea.io/gitea 55
  • Gitea 5
  • Gitea Open Source Git Server 1
61
Total CVEs
7
Critical
1
CISA KEV
1
Exploited

gitea vulnerabilities

CVEs affecting gitea, newest first. Open any entry for full detail, references, and exploit status.

61 CVEsRSS

CVE-2026-60004Critical· 9.8CISA KEV0dayPoC
3w ago

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

HadalGitea · GiteaEPSS 87%via CVEORG
GO-2026-6074None
1mo ago

Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea

Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea

Sunlitgitea · code.gitea.io/giteavia OSV
CVE-2026-34966Medium
2mo ago

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

Sunlitgitea · code.gitea.io/giteaEPSS 0.32%via OSV
CVE-2026-59765Medium
2mo ago

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

Sunlitgitea · code.gitea.io/giteaEPSS 0.30%via GHSA
CVE-2026-58429Medium· 4.9
2mo ago

Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

Sunlitgitea · code.gitea.io/giteaEPSS 0.35%via GHSA
CVE-2026-55984Low· 2.7
2mo ago

Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

Sunlitgitea · code.gitea.io/giteaEPSS 0.34%via GHSA
CVE-2026-58435Medium· 5.4
2mo ago

Gitea LFS Deploy-Key Privilege Escalation

Gitea LFS Deploy-Key Privilege Escalation

Sunlitgitea · code.gitea.io/giteaEPSS 0.19%via GHSA
CVE-2026-55987High· 8.1
2mo ago

Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)

Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)

Twilightgitea · code.gitea.io/giteaEPSS 0.29%via GHSA
CVE-2026-58437High· 7.1
2mo ago

Gitea: Repository Visibility Manipulation via Git Push Options

Gitea: Repository Visibility Manipulation via Git Push Options

Twilightgitea · code.gitea.io/giteaEPSS 0.21%via GHSA
CVE-2026-56657Medium
2mo ago

Gitea SSH Key Parser Denial of Service

Gitea SSH Key Parser Denial of Service

Sunlitgitea · code.gitea.io/giteaEPSS 0.23%via GHSA
CVE-2026-58436High
2mo ago

Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

Twilightgitea · code.gitea.io/giteaEPSS 0.34%via GHSA
CVE-2026-58314High· 7.7
2mo ago

Gitea: Two SSRF findings

Gitea: Two SSRF findings

Twilightgitea · code.gitea.io/giteaEPSS 0.29%via GHSA
CVE-2026-58419High· 7.5
2mo ago

Gitea: Notification API leaks private issue metadata after access revocation

Gitea: Notification API leaks private issue metadata after access revocation

Twilightgitea · code.gitea.io/giteaEPSS 0.51%via GHSA
CVE-2026-58422High
2mo ago

Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

Twilightgitea · code.gitea.io/giteaEPSS 0.62%via GHSA
CVE-2026-58510Medium· 4.3
2mo ago

Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

Sunlitgitea · code.gitea.io/giteaEPSS 0.21%via GHSA
CVE-2026-57897Medium· 6.5
2mo ago

Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

Sunlitgitea · code.gitea.io/giteaEPSS 0.30%via GHSA
CVE-2026-58511Low· 2.7
2mo ago

Gitea: Webhook Authorization Header Returned in Plaintext via API

Gitea: Webhook Authorization Header Returned in Plaintext via API

Sunlitgitea · code.gitea.io/giteaEPSS 0.24%via GHSA
CVE-2026-59766Medium· 4.3
2mo ago

Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`

Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`

Sunlitgitea · code.gitea.io/giteavia GHSA
CVE-2026-58439High· 8.1
2mo ago

Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

Twilightgitea · code.gitea.io/giteaEPSS 0.28%via GHSA
CVE-2026-56443Medium· 4.3
2mo ago

Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118

Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118

Sunlitgitea · code.gitea.io/giteaEPSS 0.36%via GHSA
CVE-2026-58428Medium· 6.5
2mo ago

Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

Sunlitgitea · code.gitea.io/giteaEPSS 0.33%via GHSA
CVE-2026-58432Medium· 5.9
2mo ago

Gitea: draft release attachment disclosure via missing web authorization

Gitea: draft release attachment disclosure via missing web authorization

Sunlitgitea · code.gitea.io/giteaEPSS 0.27%via GHSA
CVE-2026-56750Critical
2mo ago

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

Midnightgitea · code.gitea.io/giteaEPSS 0.34%via GHSA
CVE-2026-59763Medium
2mo ago

Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

Sunlitgitea · code.gitea.io/giteaEPSS 0.24%via GHSA
CVE-2026-58425Medium· 4.3
2mo ago

Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

Sunlitgitea · code.gitea.io/giteaEPSS 0.26%via GHSA
CVE-2026-23603Low· 3.1
2mo ago

Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

Sunlitgitea · code.gitea.io/giteaEPSS 0.25%via GHSA
CVE-2026-57886Medium· 5.9
2mo ago

Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content

Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content

Sunlitgitea · code.gitea.io/giteaEPSS 0.25%via GHSA
CVE-2026-58507Medium· 5.3
2mo ago

Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint

Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint

Sunlitgitea · code.gitea.io/giteaEPSS 0.26%via GHSA
CVE-2026-56755High
2mo ago

Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload

Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload

Twilightgitea · code.gitea.io/giteaEPSS 0.18%via GHSA
CVE-2026-56654High
2mo ago

Gitea: Privilege Escalation via Access Token Scope Escalation in API

Gitea: Privilege Escalation via Access Token Scope Escalation in API

Twilightgitea · code.gitea.io/giteaEPSS 0.42%via GHSA
gitea vulnerabilities (CVEs) · VulnSea