← Browse

Gitea

41 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-20706 CRITICAL 9.1 Gitea Open Source Git Server — Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on t…● PoC 2026-07-03 CVE-2026-20779 HIGH 7.1 Gitea Open Source Git Server — Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP cod…● PoC 2026-07-03 CVE-2026-20896 CRITICAL 9.8 Gitea Open Source Git Server — Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowin…● PoC 2026-07-03 CVE-2026-20909 MEDIUM 5.3 Gitea Open Source Git Server — Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries. 2026-07-03 CVE-2026-22547 CRITICAL 9.1 Gitea Open Source Git Server — Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limi… 2026-07-03 CVE-2026-22555 HIGH 8.1 Gitea Open Source Git Server — Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing t…● PoC 2026-07-03 CVE-2026-22874 CRITICAL 9.6 Gitea Open Source Git Server — Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list …● PoC 2026-07-03 CVE-2026-24451 HIGH 7.5 Gitea Open Source Git Server — Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private,…● PoC 2026-07-03 CVE-2026-24690 HIGH 7.5 Gitea Open Source Git Server — Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branche… 2026-07-03 CVE-2026-25038 HIGH 7.5 Gitea Open Source Git Server — Gitea 1.26.2 allows unauthorized users to access labels of private organizations.● PoC 2026-07-03 CVE-2026-25712 HIGH 7.5 Gitea Open Source Git Server — Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden me… 2026-07-03 CVE-2026-25714 MEDIUM 4.3 Gitea Open Source Git Server — Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user or…● PoC 2026-07-03 CVE-2026-25718 CRITICAL 9.1 Gitea Open Source Git Server — Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing templat… 2026-07-03 CVE-2026-25779 MEDIUM 6.1 Gitea Open Source Git Server — Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes i…● PoC 2026-07-03 CVE-2026-25782 MEDIUM 5.3 Gitea Open Source Git Server — Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue i… 2026-07-03 CVE-2026-26231 HIGH 8.5 Gitea Open Source Git Server — Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize …● PoC 2026-07-03 CVE-2026-26232 CRITICAL 9.1 Gitea Open Source Git Server — Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behav… 2026-07-03 CVE-2026-26247 CRITICAL 9.1 Gitea Open Source Git Server — Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorizati… 2026-07-03 CVE-2026-26292 CRITICAL 9.8 Gitea Open Source Git Server — Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, … 2026-07-03 CVE-2026-26307 HIGH 7.5 Gitea Open Source Git Server — Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to con… 2026-07-03 CVE-2026-27657 HIGH 7.5 Gitea Open Source Git Server — Gitea versions before 1.25.5 allow a user to change another user's primary email address. 2026-07-03 CVE-2026-27660 HIGH 7.5 Gitea Open Source Git Server — Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write… 2026-07-03 CVE-2026-27761 MEDIUM 4.3 Gitea Open Source Git Server — Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access to…● PoC 2026-07-03 CVE-2026-27771 HIGH 8.2 Gitea Open Source Git Server — Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source link…● PoC 2026-07-03 CVE-2026-27775 HIGH 8.8 Gitea Open Source Git Server — Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook ses…● PoC 2026-07-03 CVE-2026-27779 HIGH 7.5 Gitea Open Source Git Server — Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, a… 2026-07-03 CVE-2026-27780 CRITICAL 9.8 Gitea Open Source Git Server — Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook inpu… 2026-07-03 CVE-2026-27783 MEDIUM 4.3 Gitea Open Source Git Server — Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API e…● PoC 2026-07-03 CVE-2026-28699 HIGH 8.1 Gitea Open Source Git Server — Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through H…● PoC 2026-07-03 CVE-2026-28705 MEDIUM 5.3 Gitea Open Source Git Server — Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping … 2026-07-03 CVE-2026-28737 HIGH 8.7 Gitea Open Source Git Server — Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired fiel…● PoC 2026-07-03 CVE-2026-28740 HIGH 7.1 Gitea Open Source Git Server — Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for u… 2026-07-03 CVE-2026-28744 HIGH 8.1 Gitea Open Source Git Server — Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to by…● PoC 2026-07-03 CVE-2026-58418 MEDIUM 6.5 Gitea Open Source Git Server — SSRF via HTTP Redirect in Repository Migration● PoC 2026-07-03 CVE-2026-58419 HIGH 7.5 Gitea Open Source Git Server — Notification API leaks private issue metadata after access revocation● PoC 2026-07-03 CVE-2026-58421 HIGH 7.5 Gitea Open Source Git Server — Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service● PoC 2026-07-03 CVE-2026-58422 CRITICAL 9.8 Gitea Open Source Git Server — Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts● PoC 2026-07-03 CVE-2026-58423 HIGH 7.7 Gitea Open Source Git Server — LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories● PoC 2026-07-03 CVE-2026-58424 HIGH 8.9 Gitea Open Source Git Server — Permanent Fork PR Workflow Approval Gate Bypass● PoC 2026-07-03 CVE-2026-58426 CRITICAL 9.6 Gitea Open Source Git Server — Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task uplo…● PoC 2026-07-03 CVE-2026-58053 CRITICAL 9.4 Act Runner — Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to…● PoC 2026-06-28