go

code.gitea.io/gitea

View on go registry
92 Total advisories
92 Vulnerabilities
0 Malware

Vulnerabilities

HIGH 8.5
Go

CVE-2026-26231

Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo

HIGH 8.1
Go

CVE-2026-24791

Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

UNKNOWN
Go

CVE-2026-24791

Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-26231

Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-25779

Gitea: Open Redirect via redirect_to in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20706

Gitea: Token scope bypass on web archive download endpoint

HIGH 8.7
Go

CVE-2026-28737

Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer

HIGH 8.1
Go

CVE-2026-28699

Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication

HIGH 8.1
Go

CVE-2026-28744

Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens

MEDIUM 4.3
Go

CVE-2026-25714

Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw

HIGH 8.1
Go

CVE-2026-22555

Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration

UNKNOWN
Go

CVE-2026-22555

Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20706

Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-28699

Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-28744

Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-28737

Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-25714

Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea

UNKNOWN
Go

GO-2026-5091

Gitea has insecure default SSH settings

MEDIUM 4.3
Go

CVE-2026-27783

Gitea: Missing repository-unit authorization on issue-template API endpoints

UNKNOWN
Go

GHSA-3m6q-h5gj-7mrw

Gitea has insecure default SSH settings in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-27783

Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68939

Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea

HIGH 8.2
Go

CVE-2025-68939

Gitea allows attackers to add attachments with forbidden file extensions

UNKNOWN
Go

CVE-2026-20750

Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20888

Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20912

Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20897

Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20883

Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-0798

Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20904

Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20800

Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea

UNKNOWN
Go

CVE-2026-20736

Gitea has improper access control for uploaded attachments in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68945

Gitea: anonymous user can visit private user's project in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68944

Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68946

Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68941

Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68940

Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-69413

Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68942

Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68943

Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea

UNKNOWN
Go

CVE-2025-68938

Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea

UNKNOWN
Go

CVE-2021-3382

Buffer Overflow in gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2022-38183

Gitea allowed assignment of private issues in code.gitea.io/gitea

UNKNOWN
Go

CVE-2022-38795

Gitea erroneous repo clones in code.gitea.io/gitea

UNKNOWN
Go

CVE-2018-15192

Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea

UNKNOWN
Go

CVE-2019-1010261

Gitea XSS Vulnerability in code.gitea.io/gitea

UNKNOWN
Go

CVE-2022-42968

Gitea vulnerable to Argument Injection in code.gitea.io/gitea

UNKNOWN
Go

CVE-2021-45330

Improper Privilege Management in Gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2018-18926

Gitea Remote Code Execution (RCE) in code.gitea.io/gitea

UNKNOWN
Go

CVE-2021-28378

Cross-site Scripting in Gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2020-13246

Denial of Service in Gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2021-45327

Capture-replay in Gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2021-45331

Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2022-1058

Gitea Open Redirect in code.gitea.io/gitea

UNKNOWN
Go

CVE-2022-1928

Stored Cross-site Scripting in gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2022-0905

Gitea Missing Authorization vulnerability in code.gitea.io/gitea

UNKNOWN
Go

CVE-2022-30781

Shell command injection in gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2022-27313

Arbitrary file deletion in gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2021-29134

Path Traversal in Gitea in code.gitea.io/gitea

UNKNOWN
Go

CVE-2024-6886

Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea

UNKNOWN
Go

CVE-2023-3515

code.gitea.io/gitea Open Redirect vulnerability

CRITICAL 9.8
Go

CVE-2024-6886

Gitea Cross-site Scripting Vulnerability

LOW 3.0
Go

CVE-2023-3515

code.gitea.io/gitea Open Redirect vulnerability

MEDIUM 5.3
Go

CVE-2025-69413

Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists

UNKNOWN
Go

CVE-2026-0798

Gitea may send release notification emails for private repositories to users whose access has been revoked

UNKNOWN
Go

CVE-2026-20736

Gitea has improper access control for uploaded attachments

LOW 3.1
Go

CVE-2025-68940

Gitea doesn't adequately enforce branch deletion permissions after merging a pull request.

MEDIUM 4.3
Go

CVE-2025-68938

Gitea mishandles authorization for deletion of releases

MEDIUM 4.9
Go

CVE-2025-68941

Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources

MEDIUM 5.4
Go

CVE-2025-68942

Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text

MEDIUM 5.4
Go

CVE-2025-68946

Gitea vulnerable to Cross-site Scripting

MEDIUM 5.8
Go

CVE-2025-68945

Gitea: anonymous user can visit private user's project

MEDIUM 5.3
Go

CVE-2025-68943

Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order

MEDIUM 5.0
Go

CVE-2025-68944

Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries

MEDIUM 6.5
Go

CVE-2022-38183

Gitea allowed assignment of private issues

CRITICAL 9.8
Go

CVE-2021-45330

Improper Privilege Management in Gitea

CRITICAL 9.8
Go

CVE-2018-18926

Gitea Remote Code Execution (RCE)

MEDIUM 5.4
Go

CVE-2021-28378

Cross-site Scripting in Gitea

HIGH 7.5
Go

CVE-2022-27313

Arbitrary file deletion in gitea

HIGH 7.1
Go

CVE-2022-0905

Gitea Missing Authorization vulnerability

MEDIUM 4.4
Go

CVE-2022-1928

Stored Cross-site Scripting in gitea

HIGH 7.5
Go

CVE-2022-30781

Shell command injection in gitea

MEDIUM 5.3
Go

CVE-2021-29134

Path Traversal in Gitea

CRITICAL 9.8
Go

CVE-2021-45331

Reuse of one time passwords allowed in Gitea

MEDIUM 6.5
Go

CVE-2022-38795

Gitea erroneous repo clones

MEDIUM 6.1
Go

CVE-2019-1010261

Gitea XSS Vulnerability

HIGH 8.6
Go

CVE-2018-15192

Gogs and Gitea SSRF Vulnerability

MEDIUM 6.1
Go

CVE-2022-1058

Gitea Open Redirect

CRITICAL 9.8
Go

CVE-2019-11576

Gitea Allows 1FA Even for 2FA-Enrolled Accounts

MEDIUM 6.1
Go

CVE-2019-1010314

Gitea XSS Vulnerability in Repository Description

MEDIUM 6.5
Go

CVE-2019-1000002

Gitea Arbitrary File Delete Vulnerability

HIGH 7.2
Go

CVE-2020-14144

Arbitrary Code Execution in Gitea

Ready to move

Start Securing

Free, no credit card | First findings in minutes