Dependency scanning
Check whether github.com/go-gitea/gitea is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-25779
Gitea: Open Redirect via redirect_to
CVE-2019-11229
Gitea Remote Code Execution in github.com/go-gitea/gitea
CVE-2019-11228
Gitea Improper Input Validation in github.com/go-gitea/gitea
CVE-2018-1000803
Gitea Exposes Private Email Addresses in github.com/go-gitea/gitea
CVE-2021-45329
Cross-site Scripting in Gitea in github.com/go-gitea/gitea
CVE-2021-45325
Gitea displaying raw OpenID error in UI in github.com/go-gitea/gitea
CVE-2021-45328
Open redirect in Gitea in github.com/go-gitea/gitea
CVE-2021-45326
Cross Site Request Forgery in Gitea in github.com/go-gitea/gitea
CVE-2026-20888
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
CVE-2026-20904
Gitea does not properly validate ownership when toggling OpenID URI visibility
CVE-2026-20750
Gitea does not properly validate project ownership in organization project operations
CVE-2026-20800
Gitea improperly exposes issue and pull request titles
CVE-2026-20912
Gitea does not properly validate repository ownership when linking attachments to releases
CVE-2026-20897
Gitea does not properly validate repository ownership when deleting Git LFS locks
CVE-2026-20883
Gitea improperly exposes issue titles and repository names through previously started stopwatches
CVE-2022-42968
Gitea vulnerable to Argument Injection
CVE-2019-11229
Gitea Remote Code Execution
CVE-2019-11228
Gitea Improper Input Validation
CVE-2020-13246
Denial of Service in Gitea
CVE-2018-1000803
Gitea Exposes Private Email Addresses
CVE-2021-45328
Open redirect in Gitea
CVE-2021-45327
Capture-replay in Gitea
CVE-2021-45329
Cross-site Scripting in Gitea
CVE-2021-45325
Gitea displaying raw OpenID error in UI
CVE-2021-45326
Cross Site Request Forgery in Gitea
CVE-2021-3382
Buffer Overflow in gitea
CVE-2020-28991
Improper Access Control in Gitea
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes