CVE Tools

Gitea Open Source Git Server

97 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Gitea Open Source Git Server, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Gitea Open Source Git Server CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Gitea Open Source Git Server CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-019
2026-020
2026-030
2026-040
2026-050
2026-060
2026-0740
2026-0847
2026-090

Severity

How the 97 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical2223%
  • High3637%
  • Medium3435%
  • Low55%

Latest CVEs

The 15 most recently published vulnerabilities affecting Gitea Open Source Git Server.

  1. CVE-2026-24791Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes8.1
  2. CVE-2026-24059Gitea runner registration-token GET endpoint performs a write under a read-only token scope6.5
  3. CVE-2026-59765SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata7.5
  4. CVE-2026-59763Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads4.3
  5. CVE-2026-58510GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private4.3
  6. CVE-2026-58511Webhook Authorization Header Returned in Plaintext via API2.7
  7. CVE-2026-58507Private Repository Existence Disclosure via go-get Meta Endpoint5.3
  8. CVE-2026-58508Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)9.1
  9. CVE-2026-58444Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents4.3
  10. CVE-2026-58445Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API2.7
  11. CVE-2026-58442Repository migration SSRF via multi-answer DNS allow-list bypass6.5
  12. CVE-2026-58443Public-only repository tokens can update private PR head branches9.1
  13. CVE-2026-58441SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL6.3
  14. CVE-2026-58440Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)6.8
  15. CVE-2026-58438Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store