code.gitea.io/gitea vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-58443Criticalcode.gitea.io/gitea: Gitea: Public-only repository tokens can update private PR head branchesCVE-2026-58442Mediumcode.gitea.io/gitea: Gitea: Repository migration SSRF via multi-answer DNS allow-list bypassCVE-2026-58441Mediumcode.gitea.io/gitea: Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURLCVE-2026-58426Criticalcode.gitea.io/gitea: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state writeCVE-2026-58424Highcode.gitea.io/gitea: Gitea: Permanent Fork PR Workflow Approval Gate BypassCVE-2026-58423Highcode.gitea.io/gitea: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositoriesCVE-2026-58421Highcode.gitea.io/gitea: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of serviceCVE-2026-58418Mediumcode.gitea.io/gitea: Gitea: SSRF via HTTP Redirect in Repository MigrationCVE-2026-27761Mediumcode.gitea.io/gitea: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit dataCVE-2026-20896Criticalcode.gitea.io/gitea: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`CVE-2026-22874Criticalcode.gitea.io/gitea: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default FilterGHSA-RJVX-X5H2-6PX5Mediumcode.gitea.io/gitea: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation RestrictionsCVE-2026-56654Highcode.gitea.io/gitea: Gitea: Privilege Escalation via Access Token Scope Escalation in APICVE-2026-56755Highcode.gitea.io/gitea: Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package UploadCVE-2026-58507Mediumcode.gitea.io/gitea: Gitea: Private Repository Existence Disclosure via go-get Meta EndpointCVE-2026-57886Mediumcode.gitea.io/gitea: Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment contentCVE-2026-23603Lowcode.gitea.io/gitea: Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claimCVE-2026-58425Mediumcode.gitea.io/gitea: Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)CVE-2026-59763Mediumcode.gitea.io/gitea: Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploadsCVE-2026-56750Criticalcode.gitea.io/gitea: Gitea Remember-Me Token Theft Not Invalidating Attacker SessionCVE-2026-58432Mediumcode.gitea.io/gitea: Gitea: draft release attachment disclosure via missing web authorizationCVE-2026-58428Mediumcode.gitea.io/gitea: Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)CVE-2026-56443Mediumcode.gitea.io/gitea: Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR…CVE-2026-58439Highcode.gitea.io/gitea: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval FlagCVE-2026-59766Mediumcode.gitea.io/gitea: Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private…

Stop the waste.
Protect your environment with Kodem.