Gitea
121 CVEs tracked since 2022. Since Feb 2022, 1 of them reached CISA KEV.
Gitea CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2022-02 | 7 | 0 |
| 2022-03 | 3 | 0 |
| 2022-04 | null or fewer | |
| 2022-05 | 3 | 0 |
| 2022-06 | null or fewer | |
| 2022-07 | null or fewer | |
| 2022-08 | null or fewer | |
| 2022-09 | null or fewer | |
| 2022-10 | null or fewer | |
| 2022-11 | null or fewer | |
| 2022-12 | null or fewer | |
| 2023-01 | null or fewer | |
| 2023-02 | null or fewer | |
| 2023-03 | null or fewer | |
| 2023-04 | null or fewer | |
| 2023-05 | null or fewer | |
| 2023-06 | null or fewer | |
| 2023-07 | null or fewer | |
| 2023-08 | null or fewer | |
| 2023-09 | null or fewer | |
| 2023-10 | null or fewer | |
| 2023-11 | null or fewer | |
| 2023-12 | null or fewer | |
| 2024-01 | null or fewer | |
| 2024-02 | null or fewer | |
| 2024-03 | null or fewer | |
| 2024-04 | null or fewer | |
| 2024-05 | null or fewer | |
| 2024-06 | null or fewer | |
| 2024-07 | null or fewer | |
| 2024-08 | null or fewer | |
| 2024-09 | null or fewer | |
| 2024-10 | null or fewer | |
| 2024-11 | null or fewer | |
| 2024-12 | null or fewer | |
| 2025-01 | null or fewer | |
| 2025-02 | null or fewer | |
| 2025-03 | null or fewer | |
| 2025-04 | null or fewer | |
| 2025-05 | null or fewer | |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | null or fewer | |
| 2025-12 | 9 | 0 |
| 2026-01 | 10 | 0 |
| 2026-02 | null or fewer | |
| 2026-03 | null or fewer | |
| 2026-04 | null or fewer | |
| 2026-05 | null or fewer | |
| 2026-06 | null or fewer | |
| 2026-07 | 40 | 0 |
| 2026-08 | 49 | 1 |
Products
The products that kept showing up in Gitea's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Gitea.
- CVE-2026-60004Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.9.8
- CVE-2026-24791Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes8.1
- CVE-2026-24059Gitea runner registration-token GET endpoint performs a write under a read-only token scope6.5
- CVE-2026-59765SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata7.5
- CVE-2026-59763Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads4.3
- CVE-2026-58510GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private4.3
- CVE-2026-58511Webhook Authorization Header Returned in Plaintext via API2.7
- CVE-2026-58507Private Repository Existence Disclosure via go-get Meta Endpoint5.3
- CVE-2026-58508Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)9.1
- CVE-2026-58444Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents4.3
- CVE-2026-58445Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API2.7
- CVE-2026-58442Repository migration SSRF via multi-answer DNS allow-list bypass6.5
- CVE-2026-58443Public-only repository tokens can update private PR head branches9.1
- CVE-2026-58441SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL6.3
- CVE-2026-58440Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)6.8
The record
- Peak rank
- #23 in Aug 2026
- Busiest month shown
- Aug 2026, 49 CVEs
- Months with a KEV entry
- 1 since Feb 2022
- Monthly snapshots
- 7 since 2022