gitea.dev has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 7. The median CVSS is 6.3 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-863 (5).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.3
- Publish → KEV
- —
- Last 90 days
- 7 prev 0
Worst active — by depth score
CVE-2026-58440Medium· 6.8Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content37CVE-2026-58416Medium· 6.3Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)35CVE-2026-58427MediumGitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #3814528CVE-2026-58420MediumGitea: Local File Inclusion via file:// URI in Migration Restore28CVE-2026-58417MediumGitea: REST API exposes organization membership of private organizations to public28
gitea.dev vulnerabilities
CVEs affecting gitea.dev, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-58420MediumGitea: Local File Inclusion via file:// URI in Migration Restore
Gitea: Local File Inclusion via file:// URI in Migration Restore
CVE-2026-58427MediumGitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
CVE-2026-58431Medium· 4.3Gitea: Public-only API token restriction is not enforced on team API routes
Gitea: Public-only API token restriction is not enforced on team API routes
CVE-2026-58440Medium· 6.8Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content
CVE-2026-58438LowGitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
CVE-2026-58416Medium· 6.3Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
CVE-2026-58417MediumGitea: REST API exposes organization membership of private organizations to public
Gitea: REST API exposes organization membership of private organizations to public