Gitea Open Source Git Server
97 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Gitea Open Source Git Server, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
Gitea Open Source Git Server CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 9 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 40 |
| 2026-08 | 47 |
| 2026-09 | 0 |
Severity
How the 97 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical22
- High36
- Medium34
- Low5
Latest CVEs
The 15 most recently published vulnerabilities affecting Gitea Open Source Git Server.
- CVE-2026-24791Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes8.1
- CVE-2026-24059Gitea runner registration-token GET endpoint performs a write under a read-only token scope6.5
- CVE-2026-59765SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata7.5
- CVE-2026-59763Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads4.3
- CVE-2026-58510GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private4.3
- CVE-2026-58511Webhook Authorization Header Returned in Plaintext via API2.7
- CVE-2026-58507Private Repository Existence Disclosure via go-get Meta Endpoint5.3
- CVE-2026-58508Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)9.1
- CVE-2026-58444Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents4.3
- CVE-2026-58445Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API2.7
- CVE-2026-58442Repository migration SSRF via multi-answer DNS allow-list bypass6.5
- CVE-2026-58443Public-only repository tokens can update private PR head branches9.1
- CVE-2026-58441SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL6.3
- CVE-2026-58440Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)6.8
- CVE-2026-58438Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access7.5
Product grouping is registry-driven, with AI assist and human review. How it works