gitea has 61 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 46 in the last 90 days against 9 in the 90 before. The busiest recent month was July 2026 with 45. The median CVSS is 7.1 (high), with 7 rated critical. 2% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-863 (15) and CWE-200 (11). Most affected products: code.gitea.io/gitea (55), Gitea (5), Gitea Open Source Git Server (1).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 2% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 46 prev 9
Weakness classes
Products
- code.gitea.io/gitea 55
- Gitea 5
- Gitea Open Source Git Server 1
61
Total CVEs
7
Critical
1
CISA KEV
1
Exploited
Worst active — by depth score
CVE-2026-60004Critical· 9.8Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.96CVE-2024-6886Critical· 10.0Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.74CVE-2026-58424High· 8.9Gitea: Permanent Fork PR Workflow Approval Gate Bypass61CVE-2026-28699High· 8.1Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication57CVE-2026-58426Critical· 9.6Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write53
gitea vulnerabilities
CVEs affecting gitea, newest first. Open any entry for full detail, references, and exploit status.
61 CVEsRSS