55 Total advisories
55 Vulnerabilities
0 Malware

Dependency scanning

Check whether gitea.dev is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 4.3
Go

CVE-2026-56443

Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118

HIGH 7.5
Go

CVE-2026-34966

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

MEDIUM 6.2
Go

CVE-2026-56657

Gitea SSH Key Parser Denial of Service

UNKNOWN
Go KEV

CVE-2026-60004

Gitea: Remote Code Execution via diffpatch Git Hook Installation in gitea.dev

CRITICAL 9.8
Go KEV

CVE-2026-60004

Gitea: Remote Code Execution via diffpatch Git Hook Installation

UNKNOWN
Go

CVE-2026-34966

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev

UNKNOWN
Go

CVE-2026-58438

Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access

UNKNOWN
Go

CVE-2026-58417

Gitea: REST API exposes organization membership of private organizations to public

UNKNOWN
Go

CVE-2026-58427

Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

MEDIUM 4.3
Go

CVE-2026-58431

Gitea: Public-only API token restriction is not enforced on team API routes

UNKNOWN
Go

CVE-2026-56750

Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev

UNKNOWN
Go

CVE-2026-42931

Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev

UNKNOWN
Go

CVE-2026-58441

Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev

UNKNOWN
Go

CVE-2026-55987

Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev

UNKNOWN
Go

CVE-2026-58438

Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev

UNKNOWN
Go

CVE-2026-58443

Gitea: Public-only repository tokens can update private PR head branches in gitea.dev

UNKNOWN
Go

CVE-2026-58435

Gitea LFS Deploy-Key Privilege Escalation in gitea.dev

UNKNOWN
Go

CVE-2026-58425

Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev

UNKNOWN
Go

CVE-2026-58434

Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev

UNKNOWN
Go

CVE-2026-55982

Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev

UNKNOWN
Go

CVE-2026-58510

Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev

UNKNOWN
Go

CVE-2026-23603

Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev

UNKNOWN
Go

CVE-2026-58431

Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev

UNKNOWN
Go

CVE-2026-58432

Gitea: draft release attachment disclosure via missing web authorization in gitea.dev

UNKNOWN
Go

CVE-2026-59766

Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev

UNKNOWN
Go

CVE-2026-58445

Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev

UNKNOWN
Go

CVE-2026-55984

Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev

UNKNOWN
Go

CVE-2026-58427

Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev

UNKNOWN
Go

CVE-2026-58417

Gitea: REST API exposes organization membership of private organizations to public in gitea.dev

UNKNOWN
Go

CVE-2026-58507

Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev

UNKNOWN
Go

CVE-2026-58442

Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev

UNKNOWN
Go

CVE-2026-58420

Gitea: Local File Inclusion via file:// URI in Migration Restore

MEDIUM 6.3
Go

CVE-2026-58416

Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

MEDIUM 6.8
Go

CVE-2026-58440

Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content

HIGH 7.1
Go

CVE-2026-28740

Gitea: Git LFS object reuse allows non-Code access to authorize private source objects

UNKNOWN
Go

CVE-2026-56443

Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev

UNKNOWN
Go

CVE-2026-58420

Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev

UNKNOWN
Go

CVE-2026-59763

Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev

UNKNOWN
Go

CVE-2026-58314

Gitea: Two SSRF findings in gitea.dev

UNKNOWN
Go

CVE-2026-58511

Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev

UNKNOWN
Go

CVE-2026-58436

Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev

UNKNOWN
Go

CVE-2026-50105

Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev

UNKNOWN
Go

CVE-2026-54481

Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev

UNKNOWN
Go

CVE-2026-58416

Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev

UNKNOWN
Go

CVE-2026-58429

Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev

UNKNOWN
Go

CVE-2026-57894

Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev

UNKNOWN
Go

CVE-2026-58437

Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev

UNKNOWN
Go

CVE-2026-58440

Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev

UNKNOWN
Go

CVE-2026-58444

Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev

UNKNOWN
Go

CVE-2026-57897

Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev

UNKNOWN
Go

CVE-2026-58428

Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev

UNKNOWN
Go

CVE-2026-57886

Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev

UNKNOWN
Go

CVE-2026-56755

Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev

UNKNOWN
Go

CVE-2026-56657

Gitea SSH Key Parser Denial of Service in gitea.dev

UNKNOWN
Go

CVE-2026-56654

Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes