code.gitea.io/gitea
Go122 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting code.gitea.io/giteapage 3 of 3
- CVE-2026-58425MEDIUMCVSS 4.3EG 4.3fixed in 1.27.02026-07-21
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
- CVE-2026-58426CRITICALCVSS 9.6EG 9.6fixed in 1.26.22026-07-03
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
- CVE-2026-58428MEDIUMCVSS 6.5EG 6.5fixed in 1.27.02026-07-21
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
- CVE-2026-58429MEDIUMCVSS 4.9EG 4.9fixed in 1.27.02026-07-21
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
- CVE-2026-58432MEDIUMCVSS 5.9EG 5.9fixed in 1.27.02026-07-21
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
- CVE-2026-58434HIGHCVSS 7.5EG 7.5fixed in 1.27.02026-07-21
Private Repository Metadata Remains Accessible After Access Revocation
- CVE-2026-58435MEDIUMCVSS 5.4EG 5.4fixed in 1.27.02026-07-21
Gitea LFS Deploy-Key Privilege Escalation
- CVE-2026-58436HIGHCVSS 7.5EG 7.5fixed in 1.27.02026-07-21
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
- CVE-2026-58437HIGHCVSS 7.1EG 7.1fixed in 1.27.02026-07-21
Repository Visibility Manipulation via Git Push Options
- CVE-2026-58439HIGHCVSS 8.1EG 8.1fixed in 1.27.02026-07-21
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
- CVE-2026-58441MEDIUMCVSS 6.3EG 6.3fixed in 1.27.02026-07-21
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
- CVE-2026-58442MEDIUMCVSS 6.5EG 6.5fixed in 1.27.02026-07-21
Repository migration SSRF via multi-answer DNS allow-list bypass
- CVE-2026-58443CRITICALCVSS 9.1EG 9.1fixed in 1.27.02026-07-21
Public-only repository tokens can update private PR head branches
- CVE-2026-58444MEDIUMCVSS 4.3EG 4.3fixed in 1.27.02026-07-21
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
- CVE-2026-58445LOWCVSS 2.7EG 2.7fixed in 1.27.02026-07-21
Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
- CVE-2026-58507MEDIUMCVSS 5.3EG 5.3fixed in 1.27.02026-07-21
Private Repository Existence Disclosure via go-get Meta Endpoint
- CVE-2026-58510MEDIUMCVSS 4.3EG 4.3fixed in 1.27.02026-07-21
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
- CVE-2026-58511LOWCVSS 2.7EG 2.7fixed in 1.27.02026-07-21
Webhook Authorization Header Returned in Plaintext via API
- CVE-2026-59763MEDIUMCVSS 4.3EG 4.3fixed in 1.27.02026-07-21
Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
- CVE-2026-59765HIGHCVSS 7.5EG 7.5fixed in 1.27.02026-07-21
SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
- CVE-2026-59766MEDIUMCVSS 4.3EG 4.3fixed in 1.27.02026-07-21
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` ## Summary CVE-2026-20800 fixed private-info leakage to revoked…
- CVE-2026-60004CRITICALCVSS 9.8EG 9.8⚠ KEV2026-08-26
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
Check whether code.gitea.io/gitea is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for code.gitea.io/gitea CVEs against the assets you own.
Book a Demo →