Skip to content
RequestGuard Vulnerabilities
Pricing

code.gitea.io/gitea

Go package metadata, published advisories, affected versions, and known-exploitation evidence.

Go latest v1.27.3

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

v1.27.3

Published advisories match this version

2

Known exploitation

CISA KEV match

CVE-2026-60004

3

Highest advisory severity

Critical

123 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

123

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

Affected range

SEMVER: introduced 1.22.0; fixed 1.26.2

Fixed versions: 1.26.2

Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`

Affected range

SEMVER: introduced 0; fixed 1.26.3

Fixed versions: 1.26.3

Show 75 more advisories
GHSA-wrf9-r3h7-7x5v Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private
GHSA-v73x-hx65-6pf4 Gitea: Unauthorized Access to Labels of Private Organizations
GHSA-vrhc-jjfc-m3m3 Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
GHSA-v96j-25gv-g2w9 Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
GHSA-8p9h-49rc-qgxj Gitea: Repository Visibility Manipulation via Git Push Options
GHSA-2fcr-jfvc-vgg2 Gitea: Two SSRF findings
GHSA-44qc-pgvp-wx7v Gitea: Notification API leaks private issue metadata after access revocation
GHSA-649p-mmhf-85c7 Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write
GHSA-683j-3ff6-hh2x Gitea: Privilege Escalation via Access Token Scope Escalation in API
GHSA-g9g6-qhrc-p3qc Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
GHSA-94v3-77j7-vm48 Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override
GHSA-8qw8-rq86-9pc2 Gitea has insufficient permission checks for Composer package source links
GHSA-82f7-87hm-852x Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
GHSA-777r-4v59-6486 Gitea: Permanent Fork PR Workflow Approval Gate Bypass
GHSA-7wvc-rvp7-w99x Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
GHSA-fw57-jgch-pgf3 Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
GHSA-6hm7-3pwj-22rm Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
GHSA-gx3v-q759-g323 Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
GHSA-mm7c-rhg6-qr4r Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo
GHSA-wrr5-99h5-gq57 Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
GHSA-9cpj-qc93-vw8v Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer
GHSA-9r5x-wg6m-x2rc Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication
GHSA-cc8w-r4qh-3v65 Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens
GHSA-fhx7-m96w-mv29 Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration
GHSA-g7p7-x6w7-w6qg Arbitrary file deletion in gitea
GHSA-jr9c-h74f-2v28 Gitea Missing Authorization vulnerability
GHSA-p5f9-c9j9-g8qx Shell command injection in gitea
GHSA-fg3x-rwq9-74cw Gogs and Gitea SSRF Vulnerability
GHSA-3h6c-c475-jm7v Arbitrary Code Execution in Gitea
GHSA-qm72-8prh-g92x Gitea tracked-time deletion is not scoped to the requested issue
GHSA-fhq3-p242-2qpf Gitea exposes tracked time entries without repository authorization
GHSA-7jvx-g65v-r899 Gitea release asset dumps permit path traversal through crafted names
GHSA-2wm4-vwp6-v7xc Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
GHSA-rjvx-x5h2-6px5 Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions
GHSA-mg4f-x9v4-6h2p Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
GHSA-rqhx-647v-wx32 Gitea: SSRF via HTTP Redirect in Repository Migration
GHSA-wwqq-x6w4-frm2 Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
GHSA-rh79-75qm-gwjr Gitea LFS Deploy-Key Privilege Escalation
GHSA-q9pg-jj6x-j9p6 Gitea: draft release attachment disclosure via missing web authorization
GHSA-xmj7-xj85-hfc3 Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
GHSA-qf2f-qh6p-7v89 Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`
GHSA-q423-49rw-g9mh Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
GHSA-h2x6-g7q6-344v Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass
GHSA-p4mj-98mv-xq26 Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint
GHSA-vxv2-8j6r-pcpg Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
GHSA-7p4h-3gxq-x3h3 Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
GHSA-frpw-3h2q-4jj6 Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
GHSA-6c6r-5xr4-cr5m Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
GHSA-4xjf-493q-98p3 Gitea SSH Key Parser Denial of Service
GHSA-25gq-j9jx-43pg Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
GHSA-cp3q-vrj2-ghhh Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
GHSA-9mq6-mqjj-c2c5 Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
GHSA-fq2p-5p22-8g6j Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
GHSA-6cqf-375w-639g Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
GHSA-3pww-vcvm-3gmj Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data
GHSA-cr4g-f395-h25h Gitea: Token scope bypass on web archive download endpoint
GHSA-8629-vc8r-5p58 Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw
GHSA-3m6q-h5gj-7mrw Gitea has insecure default SSH settings
GHSA-3fwp-p5rj-2pxf Gitea: Missing repository-unit authorization on issue-template API endpoints
GHSA-pc73-rj2c-wvf9 Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists
GHSA-cm54-pfmc-xrwx Gitea mishandles authorization for deletion of releases
GHSA-xfq3-qj7j-4565 Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources
GHSA-898p-hh3p-hf9r Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text
GHSA-hq57-c72x-4774 Gitea vulnerable to Cross-site Scripting
GHSA-7xq4-mwcp-q8fx Gitea: anonymous user can visit private user's project
GHSA-jhx5-4vr4-f327 Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order
GHSA-f85h-c7m6-cfpm Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries
GHSA-fhv8-m4j4-cww2 Gitea allowed assignment of private issues
GHSA-g95p-88p4-76cm Cross-site Scripting in Gitea
GHSA-ph3w-2843-72mx Stored Cross-site Scripting in gitea
GHSA-h3q4-vmw4-cpr5 Path Traversal in Gitea
GHSA-8j3v-68w3-3848 Gitea erroneous repo clones
GHSA-5rh7-6gfj-mc87 Gitea XSS Vulnerability
GHSA-4rqq-rxvc-v2rc Gitea Open Redirect
GHSA-hqx2-j33x-9fc4 Gitea XSS Vulnerability in Repository Description