github.com/go-gitea/gitea
Go20 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/go-gitea/giteapage 1 of 1
- CVE-2018-1000803MEDIUMCVSS 5.3EG 5.3fixed in 1.5.12018-10-08
Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appear to be exploitable via Watch a repository to receive email notifications. Emails received…
- CVE-2019-11228HIGHCVSS 7.5EG 7.5fixed in 1.7.62019-04-15
repo/setting.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 does not validate the form.MirrorAddress before calling SaveAddress.
- CVE-2019-11229HIGHCVSS 8.8EG 8.9fixed in 1.7.62019-04-15
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.
- CVE-2020-13246HIGHCVSS 7.5EG 7.5fixed in 1.12.02020-05-20
An issue was discovered in Gitea through 1.11.5. An attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another.
- CVE-2020-28991CRITICALCVSS 9.8EG 9.8fixed in 1.12.62020-11-24
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go.
- CVE-2021-3382HIGHCVSS 7.5EG 7.5fixed in 1.13.22021-02-05
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path.
- CVE-2021-45325HIGHCVSS 7.5EG 7.5fixed in 1.7.02022-02-08
Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.
- CVE-2021-45326HIGHCVSS 8.8EG 8.8fixed in 1.5.22022-02-08
Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST requests.
- CVE-2021-45327CRITICALCVSS 9.8EG 9.8fixed in 1.11.22022-02-08
Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code.
- CVE-2021-45328MEDIUMCVSS 6.1EG 6.1fixed in 1.4.32022-02-08
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
- CVE-2021-45329MEDIUMCVSS 6.1EG 6.1fixed in 1.5.12022-02-08
Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field.
- CVE-2022-42968CRITICALCVSS 9.8EG 9.8fixed in 1.17.32022-10-16
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.
- CVE-2026-20750CRITICALCVSS 9.1EG 9.1fixed in 1.25.42026-01-22
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization.
- CVE-2026-20800MEDIUMCVSS 6.5EG 6.5fixed in 1.25.42026-01-22
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously…
- CVE-2026-20883MEDIUMCVSS 6.5EG 6.5fixed in 1.25.42026-01-22
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches.
- CVE-2026-20888MEDIUMCVSS 4.3EG 4.3fixed in 1.25.42026-01-22
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.
- CVE-2026-20897CRITICALCVSS 9.1EG 9.1fixed in 1.25.42026-01-22
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.
- CVE-2026-20904MEDIUMCVSS 6.5EG 6.5fixed in 1.25.42026-01-22
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.
- CVE-2026-20912CRITICALCVSS 9.1EG 9.1fixed in 1.25.42026-01-22
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to u…
- CVE-2026-25779MEDIUMCVSS 6.1EG 6.1fixed in 1.26.02026-06-17
Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect_to values.
Check whether github.com/go-gitea/gitea is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/go-gitea/gitea CVEs against the assets you own.
Book a Demo →