VulnSea

gitea has 61 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 46 in the last 90 days against 9 in the 90 before. The busiest recent month was July 2026 with 45. The median CVSS is 7.1 (high), with 7 rated critical. 2% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-863 (15) and CWE-200 (11). Most affected products: code.gitea.io/gitea (55), Gitea (5), Gitea Open Source Git Server (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
2% vs 1% corpus
Median CVSS
7.1
Publish → KEV
Last 90 days
46 prev 9

Products

  • code.gitea.io/gitea 55
  • Gitea 5
  • Gitea Open Source Git Server 1
61
Total CVEs
7
Critical
1
CISA KEV
1
Exploited

gitea vulnerabilities

CVEs affecting gitea, newest first. Open any entry for full detail, references, and exploit status.

61 CVEsRSS

GHSA-rjvx-x5h2-6px5Medium
2mo ago

Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions

Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions

Sunlitgitea · code.gitea.io/giteavia GHSA
CVE-2026-58418Medium· 6.5
2mo ago

Gitea: SSRF via HTTP Redirect in Repository Migration

Gitea: SSRF via HTTP Redirect in Repository Migration

Sunlitgitea · code.gitea.io/giteaEPSS 0.41%via GHSA
CVE-2026-58421High· 7.5
2mo ago

Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

Twilightgitea · code.gitea.io/giteaEPSS 0.58%via GHSA
CVE-2026-58423High· 7.7
2mo ago

Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories

Twilightgitea · code.gitea.io/giteaEPSS 0.54%via GHSA
CVE-2026-58424High· 8.9PoC
2mo ago

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

Gitea: Permanent Fork PR Workflow Approval Gate Bypass

Midnightgitea · code.gitea.io/giteaEPSS 0.37%via GHSA
CVE-2026-58426Critical· 9.6
2mo ago

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

Midnightgitea · code.gitea.io/giteaEPSS 0.30%via GHSA
CVE-2026-58441Medium· 6.3
2mo ago

Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL

Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL

Sunlitgitea · code.gitea.io/giteaEPSS 0.16%via GHSA
CVE-2026-58442Medium· 6.5
2mo ago

Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass

Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass

Sunlitgitea · code.gitea.io/giteaEPSS 0.24%via GHSA
CVE-2026-58444Medium· 4.3
2mo ago

Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

Sunlitgitea · code.gitea.io/giteaEPSS 0.24%via GHSA
CVE-2026-58445Low· 2.7
2mo ago

Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

Sunlitgitea · code.gitea.io/giteaEPSS 0.23%via GHSA
CVE-2026-42931Medium· 6.5
2mo ago

Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

Sunlitgitea · code.gitea.io/giteaEPSS 0.38%via GHSA
CVE-2026-50105Medium· 4.3
2mo ago

Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

Sunlitgitea · code.gitea.io/giteaEPSS 0.29%via GHSA
CVE-2026-54481High· 7.5
2mo ago

Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override

Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override

Twilightgitea · code.gitea.io/giteaEPSS 0.29%via GHSA
CVE-2026-58434Low
2mo ago

Gitea: Private Repository Metadata Remains Accessible After Access Revocation

Gitea: Private Repository Metadata Remains Accessible After Access Revocation

Sunlitgitea · code.gitea.io/giteaEPSS 0.28%via GHSA
CVE-2026-55982Medium
2mo ago

Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

Sunlitgitea · code.gitea.io/giteaEPSS 0.37%via GHSA
CVE-2026-57894High· 8.5
2mo ago

Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

Twilightgitea · code.gitea.io/giteaEPSS 0.27%via GHSA
CVE-2026-22555High· 8.1
3mo ago

Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration

Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration

Twilightgitea · code.gitea.io/giteaEPSS 0.43%via GHSA
CVE-2026-24791High· 8.1
3mo ago

Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

Twilightgitea · code.gitea.io/giteaEPSS 0.25%via GHSA
CVE-2026-28737High· 8.7
3mo ago

Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer

Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer

Twilightgitea · code.gitea.io/giteaEPSS 0.43%via GHSA
CVE-2026-28744High· 8.1
3mo ago

Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens

Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens

Twilightgitea · code.gitea.io/giteaEPSS 0.45%via GHSA
CVE-2026-28699High· 8.1PoC
3mo ago

Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication

Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication

Midnightgitea · code.gitea.io/giteaEPSS 0.55%via GHSA
CVE-2026-26231High· 8.5
3mo ago

Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo

Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo

Twilightgitea · code.gitea.io/giteaEPSS 0.35%via GHSA
CVE-2026-25714Medium· 4.3
3mo ago

Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw

Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw

Sunlitgitea · code.gitea.io/giteaEPSS 0.34%via GHSA
CVE-2026-27783Medium· 4.3
3mo ago

Gitea: Missing repository-unit authorization on issue-template API endpoints

Gitea: Missing repository-unit authorization on issue-template API endpoints

Sunlitgitea · code.gitea.io/giteaEPSS 0.34%via GHSA
CVE-2026-20706Medium
3mo ago

Gitea: Token scope bypass on web archive download endpoint

Gitea: Token scope bypass on web archive download endpoint

Sunlitgitea · code.gitea.io/giteaEPSS 0.56%via GHSA
CVE-2026-20736High· 7.5
8mo ago

Gitea does not properly verify repository context when deleting attachments

Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a dif…

Twilightgitea · giteaEPSS 0.44%via NVD
CVE-2026-20912Critical· 9.1
8mo ago

Gitea does not properly validate repository ownership when linking attachments to releases

Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to…

Midnightgitea · giteaEPSS 0.46%via NVD
CVE-2026-20897Critical· 9.1
8mo ago

Gitea does not properly validate repository ownership when deleting Git LFS locks

Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.

Midnightgitea · giteaEPSS 0.46%via NVD
CVE-2026-20750Critical· 9.1
8mo ago

Gitea does not properly validate project ownership in organization project operations

Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization.

Midnightgitea · giteaEPSS 0.44%via NVD
CVE-2025-68939High· 8.2
8mo ago

Gitea allows attackers to add attachments with forbidden file extensions

Gitea allows attackers to add attachments with forbidden file extensions

Twilightgitea · code.gitea.io/giteaEPSS 0.33%via OSV
gitea vulnerabilities (CVEs) — page 2 · VulnSea