Gitea open source git server
This hub aggregates every CVE we track for Gitea open source git server, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
50
CVEs tracked
15
Critical
22
High
0
In CISA KEV
Severity distribution
HIGH22CRITICAL15MEDIUM12LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
9
0
0
0
0
0
40
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Gitea open source git server.
- CVE-2026-58426Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write9.6
- CVE-2026-58422Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts9.8
- CVE-2026-58424Permanent Fork PR Workflow Approval Gate Bypass8.9
- CVE-2026-58423LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories7.7
- CVE-2026-58421Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service7.5
- CVE-2026-58419Notification API leaks private issue metadata after access revocation7.5
- CVE-2026-58418SSRF via HTTP Redirect in Repository Migration6.5
- CVE-2026-28744Gitea Git smart HTTP bypasses repository token scopes for bearer tokens8.1
- CVE-2026-28737Gitea 3D file viewer allows stored XSS through glTF extensionsRequired8.7
- CVE-2026-28705Gitea repository dumps write release assets using unsafe path names5.3
- CVE-2026-28740Gitea LFS object reuse bypasses Code-unit authorization7.1
- CVE-2026-27783Gitea issue-template APIs bypass repository unit authorization4.3
- CVE-2026-28699Gitea Basic Auth bypasses OAuth2 access token scopes8.1
- CVE-2026-27779Gitea forwarded-proto handling allows public URL spoofing7.5
- CVE-2026-27780Gitea pre-receive hook can miss branch-protection checks after scanner errors9.8
Product normalization is registry-driven with AI assist and human review. How it works