code.gitea.io/gitea vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-57894Highcode.gitea.io/gitea: Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository ExfiltrationCVE-2026-27771Highcode.gitea.io/gitea: Gitea has insufficient permission checks for Composer package source linksCVE-2026-27779Highcode.gitea.io/gitea: Gitea forwarded-proto validation allows canonical URL spoofingCVE-2026-27780Criticalcode.gitea.io/gitea: Gitea pre-receive hook scanner errors allow branch-protection bypassCVE-2026-28705Mediumcode.gitea.io/gitea: Gitea release asset dumps permit path traversal through crafted namesCVE-2026-27660Highcode.gitea.io/gitea: Gitea draft releases and attachments are exposed without write permissionCVE-2026-26307Highcode.gitea.io/gitea: Gitea git grep searches allow server resource exhaustionCVE-2026-25782Mediumcode.gitea.io/gitea: Gitea tracked-time deletion is not scoped to the requested issueCVE-2026-25718Criticalcode.gitea.io/gitea: Gitea template repository generation follows unsafe filesystem pathsCVE-2026-25712Highcode.gitea.io/gitea: Gitea organization permission APIs expose hidden membership and private organization dataCVE-2026-24690Highcode.gitea.io/gitea: Gitea pull request branch permission checks allow unauthorized updates and rebasesCVE-2026-26232Criticalcode.gitea.io/gitea: Gitea OAuth2 authorization codes can be reused after expiryCVE-2026-20909Mediumcode.gitea.io/gitea: Gitea exposes tracked time entries without repository authorizationCVE-2026-27657Highcode.gitea.io/gitea: Gitea primary email ownership bypass allows cross-user email changesCVE-2026-26292Criticalcode.gitea.io/gitea: Gitea LFS mirror operations bypass migration HTTP transport protectionsCVE-2026-26247Criticalcode.gitea.io/gitea: Gitea OAuth2 PKCE S256 verifier bypassCVE-2026-22547Criticalcode.gitea.io/gitea: Gitea repository creation accepts insufficiently validated fieldsCVE-2026-28737Highcode.gitea.io/gitea: Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File ViewerCVE-2026-24791Highcode.gitea.io/gitea: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routesCVE-2026-22555Highcode.gitea.io/gitea: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret ExfiltrationCVE-2026-20706Mediumcode.gitea.io/gitea: Gitea: Token scope bypass on web archive download endpointCVE-2026-27783Mediumcode.gitea.io/gitea: Gitea: Missing repository-unit authorization on issue-template API endpointsCVE-2026-25714Mediumcode.gitea.io/gitea: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flawCVE-2026-26231Highcode.gitea.io/gitea: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repoCVE-2026-28699Highcode.gitea.io/gitea: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication

Stop the waste.
Protect your environment with Kodem.