gitea
DevTools & CIoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting gitea.
- CVE-2026-60004Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.KEV9.8
- CVE-2026-24059Gitea runner registration-token GET endpoint performs a write under a read-only token scope6.5
- CVE-2026-24791Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes8.1
- CVE-2026-59765SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata7.5
- CVE-2026-59763Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads4.3
- CVE-2026-58510GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private4.3
- CVE-2026-58511Webhook Authorization Header Returned in Plaintext via API2.7
- CVE-2026-58507Private Repository Existence Disclosure via go-get Meta Endpoint5.3
- CVE-2026-58508Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)9.1
- CVE-2026-58444Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents4.3
- CVE-2026-58445Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API2.7
- CVE-2026-58442Repository migration SSRF via multi-answer DNS allow-list bypass6.5
- CVE-2026-58443Public-only repository tokens can update private PR head branches9.1
- CVE-2026-58441SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL6.3
- CVE-2026-58440Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)6.8