go

github.com/go-gitea/gitea

View on go registry
27 Total advisories
27 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/go-gitea/gitea is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
Go

CVE-2026-25779

Gitea: Open Redirect via redirect_to

UNKNOWN
Go

CVE-2019-11229

Gitea Remote Code Execution in github.com/go-gitea/gitea

UNKNOWN
Go

CVE-2019-11228

Gitea Improper Input Validation in github.com/go-gitea/gitea

UNKNOWN
Go

CVE-2018-1000803

Gitea Exposes Private Email Addresses in github.com/go-gitea/gitea

UNKNOWN
Go

CVE-2021-45329

Cross-site Scripting in Gitea in github.com/go-gitea/gitea

UNKNOWN
Go

CVE-2021-45325

Gitea displaying raw OpenID error in UI in github.com/go-gitea/gitea

UNKNOWN
Go

CVE-2021-45328

Open redirect in Gitea in github.com/go-gitea/gitea

UNKNOWN
Go

CVE-2021-45326

Cross Site Request Forgery in Gitea in github.com/go-gitea/gitea

UNKNOWN
Go

CVE-2026-20888

Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface

UNKNOWN
Go

CVE-2026-20904

Gitea does not properly validate ownership when toggling OpenID URI visibility

UNKNOWN
Go

CVE-2026-20750

Gitea does not properly validate project ownership in organization project operations

UNKNOWN
Go

CVE-2026-20800

Gitea improperly exposes issue and pull request titles

UNKNOWN
Go

CVE-2026-20912

Gitea does not properly validate repository ownership when linking attachments to releases

UNKNOWN
Go

CVE-2026-20897

Gitea does not properly validate repository ownership when deleting Git LFS locks

UNKNOWN
Go

CVE-2026-20883

Gitea improperly exposes issue titles and repository names through previously started stopwatches

CRITICAL 9.8
Go

CVE-2022-42968

Gitea vulnerable to Argument Injection

HIGH 8.1
Go

CVE-2019-11229

Gitea Remote Code Execution

HIGH 7.5
Go

CVE-2019-11228

Gitea Improper Input Validation

HIGH 7.5
Go

CVE-2020-13246

Denial of Service in Gitea

MEDIUM 5.3
Go

CVE-2018-1000803

Gitea Exposes Private Email Addresses

MEDIUM 6.1
Go

CVE-2021-45328

Open redirect in Gitea

CRITICAL 9.8
Go

CVE-2021-45327

Capture-replay in Gitea

MEDIUM 6.1
Go

CVE-2021-45329

Cross-site Scripting in Gitea

MEDIUM 5.3
Go

CVE-2021-45325

Gitea displaying raw OpenID error in UI

HIGH 8.8
Go

CVE-2021-45326

Cross Site Request Forgery in Gitea

HIGH 7.0
Go

CVE-2021-3382

Buffer Overflow in gitea

CRITICAL 9.8
Go

CVE-2020-28991

Improper Access Control in Gitea

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes