gitea has 61 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 46 in the last 90 days against 9 in the 90 before. The busiest recent month was July 2026 with 45. The median CVSS is 7.1 (high), with 7 rated critical. 2% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-863 (15) and CWE-200 (11). Most affected products: code.gitea.io/gitea (55), Gitea (5), Gitea Open Source Git Server (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 2% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 46 prev 9
Weakness classes
Products
- code.gitea.io/gitea 55
- Gitea 5
- Gitea Open Source Git Server 1
Worst active — by depth score
CVE-2026-60004Critical· 9.8Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.96CVE-2024-6886Critical· 10.0Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.74CVE-2026-58424High· 8.9Gitea: Permanent Fork PR Workflow Approval Gate Bypass61CVE-2026-28699High· 8.1Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication57CVE-2026-58426Critical· 9.6Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write53
gitea vulnerabilities
CVEs affecting gitea, newest first. Open any entry for full detail, references, and exploit status.
61 CVEsRSS
GHSA-rjvx-x5h2-6px5MediumGitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions
Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions
CVE-2026-58418Medium· 6.5Gitea: SSRF via HTTP Redirect in Repository Migration
Gitea: SSRF via HTTP Redirect in Repository Migration
CVE-2026-58421High· 7.5Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
CVE-2026-58423High· 7.7Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
CVE-2026-58424High· 8.9PoCGitea: Permanent Fork PR Workflow Approval Gate Bypass
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
CVE-2026-58426Critical· 9.6Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
CVE-2026-58441Medium· 6.3Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
CVE-2026-58442Medium· 6.5Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass
CVE-2026-58444Medium· 4.3Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
CVE-2026-58445Low· 2.7Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
CVE-2026-42931Medium· 6.5Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
CVE-2026-50105Medium· 4.3Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
CVE-2026-54481High· 7.5Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override
CVE-2026-58434LowGitea: Private Repository Metadata Remains Accessible After Access Revocation
Gitea: Private Repository Metadata Remains Accessible After Access Revocation
CVE-2026-55982MediumGitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
CVE-2026-57894High· 8.5Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
CVE-2026-22555High· 8.1Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration
Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration
CVE-2026-24791High· 8.1Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
CVE-2026-28737High· 8.7Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer
Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer
CVE-2026-28744High· 8.1Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens
Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens
CVE-2026-28699High· 8.1PoCGitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication
Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication
CVE-2026-26231High· 8.5Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo
Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo
CVE-2026-25714Medium· 4.3Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw
Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw
CVE-2026-27783Medium· 4.3Gitea: Missing repository-unit authorization on issue-template API endpoints
Gitea: Missing repository-unit authorization on issue-template API endpoints
CVE-2026-20706MediumGitea: Token scope bypass on web archive download endpoint
Gitea: Token scope bypass on web archive download endpoint
CVE-2026-20736High· 7.5Gitea does not properly verify repository context when deleting attachments
Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a dif…
CVE-2026-20912Critical· 9.1Gitea does not properly validate repository ownership when linking attachments to releases
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to…
CVE-2026-20897Critical· 9.1Gitea does not properly validate repository ownership when deleting Git LFS locks
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.
CVE-2026-20750Critical· 9.1Gitea does not properly validate project ownership in organization project operations
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization.
CVE-2025-68939High· 8.2Gitea allows attackers to add attachments with forbidden file extensions
Gitea allows attackers to add attachments with forbidden file extensions