Gitea open source git server
This hub aggregates every CVE we track for Gitea open source git server, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
97
CVEs tracked
22
Critical
36
High
0
In CISA KEV
Severity distribution
HIGH36MEDIUM34CRITICAL22LOW5
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
9
0
0
0
0
0
40
47
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Gitea open source git server.
- CVE-2026-24059Gitea runner registration-token GET endpoint performs a write under a read-only token scope6.5
- CVE-2026-24791Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes8.1
- CVE-2026-59765SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata7.5
- CVE-2026-59763Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads4.3
- CVE-2026-58510GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private4.3
- CVE-2026-58511Webhook Authorization Header Returned in Plaintext via API2.7
- CVE-2026-58507Private Repository Existence Disclosure via go-get Meta Endpoint5.3
- CVE-2026-58508Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)9.1
- CVE-2026-58444Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents4.3
- CVE-2026-58445Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API2.7
- CVE-2026-58442Repository migration SSRF via multi-answer DNS allow-list bypass6.5
- CVE-2026-58443Public-only repository tokens can update private PR head branches9.1
- CVE-2026-58441SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL6.3
- CVE-2026-58440Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)6.8
- CVE-2026-58438Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access7.5
Product normalization is registry-driven with AI assist and human review. How it works