gitea.dev vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-58431Mediumgitea.dev: Gitea: Public-only API token restriction is not enforced on team API routesCVE-2026-58427Mediumgitea.dev: Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145CVE-2026-58420Mediumgitea.dev: Gitea: Local File Inclusion via file:// URI in Migration RestoreCVE-2026-58417Mediumgitea.dev: Gitea: REST API exposes organization membership of private organizations to publicCVE-2026-58416Mediumgitea.dev: Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)CVE-2026-58438Lowgitea.dev: Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot accessCVE-2026-28740Highgitea.dev: Gitea: Git LFS object reuse allows non-Code access to authorize private source objectsCVE-2026-58440Mediumgitea.dev: Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo…

Stop the waste.
Protect your environment with Kodem.