go

code.gitea.io/gitea

View on go registry
92 Total advisories
92 Vulnerabilities
0 Malware

Dependency scanning

Check whether code.gitea.io/gitea is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 8.5
Go

CVE-2026-26231

Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo

HIGH 8.1
Go

CVE-2026-24791

Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

UNKNOWN
Go

CVE-2026-24791

Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-26231

Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-25779

Gitea: Open Redirect via redirect_to in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20706

Gitea: Token scope bypass on web archive download endpoint

HIGH 8.7
Go

CVE-2026-28737

Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer

HIGH 8.1
Go

CVE-2026-28699

Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication

HIGH 8.1
Go

CVE-2026-28744

Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens

MEDIUM 4.3
Go

CVE-2026-25714

Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw

HIGH 8.1
Go

CVE-2026-22555

Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration

UNKNOWN
Go

CVE-2026-22555

Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20706

Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-28699

Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-28744

Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-28737

Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-25714

Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea

UNKNOWN
Go

GO-2026-5091

Gitea has insecure default SSH settings

MEDIUM 4.3
Go

CVE-2026-27783

Gitea: Missing repository-unit authorization on issue-template API endpoints

UNKNOWN
Go

GHSA-3m6q-h5gj-7mrw

Gitea has insecure default SSH settings in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-27783

Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68939

Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea

HIGH 8.2
Go

CVE-2025-68939

Gitea allows attackers to add attachments with forbidden file extensions

UNKNOWN
Go

CVE-2026-20750

Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20888

Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20912

Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20897

Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20883

Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-0798

Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20904

Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20800

Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20736

Gitea has improper access control for uploaded attachments in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68945

Gitea: anonymous user can visit private user's project in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68944

Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68946

Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68941

Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68940

Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-69413

Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68942

Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68943

Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68938

Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea

UNKNOWN
Go

CVE-2021-3382

Buffer Overflow in gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2022-38183

Gitea allowed assignment of private issues in code.gitea.io/gitea

UNKNOWN
Go

CVE-2022-38795

Gitea erroneous repo clones in code.gitea.io/gitea

UNKNOWN
Go

CVE-2018-15192

Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea

UNKNOWN
Go

CVE-2019-1010261

Gitea XSS Vulnerability in code.gitea.io/gitea

UNKNOWN
Go

CVE-2022-42968

Gitea vulnerable to Argument Injection in code.gitea.io/gitea

UNKNOWN
Go

CVE-2021-45330

Improper Privilege Management in Gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2018-18926

Gitea Remote Code Execution (RCE) in code.gitea.io/gitea

UNKNOWN
Go

CVE-2021-28378

Cross-site Scripting in Gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2020-13246

Denial of Service in Gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2021-45327

Capture-replay in Gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2021-45331

Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2022-1058

Gitea Open Redirect in code.gitea.io/gitea

UNKNOWN
Go

CVE-2022-1928

Stored Cross-site Scripting in gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2022-0905

Gitea Missing Authorization vulnerability in code.gitea.io/gitea

UNKNOWN
Go

CVE-2022-30781

Shell command injection in gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2022-27313

Arbitrary file deletion in gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2021-29134

Path Traversal in Gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2024-6886

Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea

UNKNOWN
Go

CVE-2023-3515

code.gitea.io/gitea Open Redirect vulnerability

CRITICAL 9.8
Go

CVE-2024-6886

Gitea Cross-site Scripting Vulnerability

LOW 3.0
Go

CVE-2023-3515

code.gitea.io/gitea Open Redirect vulnerability

MEDIUM 5.3
Go

CVE-2025-69413

Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists

UNKNOWN
Go

CVE-2026-0798

Gitea may send release notification emails for private repositories to users whose access has been revoked

UNKNOWN
Go

CVE-2026-20736

Gitea has improper access control for uploaded attachments

LOW 3.1
Go

CVE-2025-68940

Gitea doesn't adequately enforce branch deletion permissions after merging a pull request.

MEDIUM 4.3
Go

CVE-2025-68938

Gitea mishandles authorization for deletion of releases

MEDIUM 4.9
Go

CVE-2025-68941

Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources

MEDIUM 5.4
Go

CVE-2025-68942

Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text

MEDIUM 5.4
Go

CVE-2025-68946

Gitea vulnerable to Cross-site Scripting

MEDIUM 5.8
Go

CVE-2025-68945

Gitea: anonymous user can visit private user's project

MEDIUM 5.3
Go

CVE-2025-68943

Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order

MEDIUM 5.0
Go

CVE-2025-68944

Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries

MEDIUM 6.5
Go

CVE-2022-38183

Gitea allowed assignment of private issues

CRITICAL 9.8
Go

CVE-2021-45330

Improper Privilege Management in Gitea

CRITICAL 9.8
Go

CVE-2018-18926

Gitea Remote Code Execution (RCE)

MEDIUM 5.4
Go

CVE-2021-28378

Cross-site Scripting in Gitea

HIGH 7.5
Go

CVE-2022-27313

Arbitrary file deletion in gitea

HIGH 7.1
Go

CVE-2022-0905

Gitea Missing Authorization vulnerability

MEDIUM 4.4
Go

CVE-2022-1928

Stored Cross-site Scripting in gitea

HIGH 7.5
Go

CVE-2022-30781

Shell command injection in gitea

MEDIUM 5.3
Go

CVE-2021-29134

Path Traversal in Gitea

CRITICAL 9.8
Go

CVE-2021-45331

Reuse of one time passwords allowed in Gitea

MEDIUM 6.5
Go

CVE-2022-38795

Gitea erroneous repo clones

MEDIUM 6.1
Go

CVE-2019-1010261

Gitea XSS Vulnerability

HIGH 8.6
Go

CVE-2018-15192

Gogs and Gitea SSRF Vulnerability

MEDIUM 6.1
Go

CVE-2022-1058

Gitea Open Redirect

CRITICAL 9.8
Go

CVE-2019-11576

Gitea Allows 1FA Even for 2FA-Enrolled Accounts

MEDIUM 6.1
Go

CVE-2019-1010314

Gitea XSS Vulnerability in Repository Description

MEDIUM 6.5
Go

CVE-2019-1000002

Gitea Arbitrary File Delete Vulnerability

HIGH 7.2
Go

CVE-2020-14144

Arbitrary Code Execution in Gitea

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes