VulnSea

gitea.dev has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 7. The median CVSS is 6.3 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-863 (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.3
Publish → KEV
Last 90 days
7 prev 0

Products

  • gitea.dev 7
7
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

gitea.dev vulnerabilities

CVEs affecting gitea.dev, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-58420Medium
2mo ago

Gitea: Local File Inclusion via file:// URI in Migration Restore

Gitea: Local File Inclusion via file:// URI in Migration Restore

Sunlitgitea.dev · gitea.devEPSS 0.41%via GHSA
CVE-2026-58427Medium
2mo ago

Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

Sunlitgitea.dev · gitea.devEPSS 0.34%via GHSA
CVE-2026-58431Medium· 4.3
2mo ago

Gitea: Public-only API token restriction is not enforced on team API routes

Gitea: Public-only API token restriction is not enforced on team API routes

Sunlitgitea.dev · gitea.devEPSS 0.21%via GHSA
CVE-2026-58440Medium· 6.8
2mo ago

Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content

Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content

Sunlitgitea.dev · gitea.devEPSS 0.28%via GHSA
CVE-2026-58438Low
2mo ago

Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access

Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access

Sunlitgitea.dev · gitea.devEPSS 0.27%via GHSA
CVE-2026-58416Medium· 6.3
2mo ago

Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

Sunlitgitea.dev · gitea.devEPSS 0.25%via GHSA
CVE-2026-58417Medium
2mo ago

Gitea: REST API exposes organization membership of private organizations to public

Gitea: REST API exposes organization membership of private organizations to public

Sunlitgitea.dev · gitea.devEPSS 0.34%via GHSA
gitea.dev vulnerabilities (CVEs) · VulnSea