CVE Tools

Gitea

121 CVEs tracked since 2022. Since Feb 2022, 1 of them reached CISA KEV.

Gitea CVEs per month

Feb 2022 to Aug 2026. Point at a month, or focus the strip and use the arrow keys.
Gitea CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-0270
2022-0330
2022-04null or fewer
2022-0530
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-1290
2026-01100
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-06null or fewer
2026-07400
2026-08491

Products

The products that kept showing up in Gitea's monthly top three, with their CVEs summed over those months.

  1. Gitea Open Source Git Server963 months
  2. Gitea346 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Gitea.

  1. CVE-2026-60004Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.9.8
  2. CVE-2026-24791Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes8.1
  3. CVE-2026-24059Gitea runner registration-token GET endpoint performs a write under a read-only token scope6.5
  4. CVE-2026-59765SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata7.5
  5. CVE-2026-59763Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads4.3
  6. CVE-2026-58510GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private4.3
  7. CVE-2026-58511Webhook Authorization Header Returned in Plaintext via API2.7
  8. CVE-2026-58507Private Repository Existence Disclosure via go-get Meta Endpoint5.3
  9. CVE-2026-58508Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)9.1
  10. CVE-2026-58444Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents4.3
  11. CVE-2026-58445Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API2.7
  12. CVE-2026-58442Repository migration SSRF via multi-answer DNS allow-list bypass6.5
  13. CVE-2026-58443Public-only repository tokens can update private PR head branches9.1
  14. CVE-2026-58441SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL6.3
  15. CVE-2026-58440Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)6.8

The record

Peak rank
#23 in Aug 2026
Busiest month shown
Aug 2026, 49 CVEs
Months with a KEV entry
1 since Feb 2022
Monthly snapshots
7 since 2022
Gitea's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store