gitea.dev
Activity
- Latest release
- May 20, 2026
- Total releases
- 50
- Cadence
- ~40 days
- Last 12 months
- 3
Details
- First release
- Oct 17, 2016
| Version | Released | |
|---|---|---|
v1.26.2
patch
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.26.2
patch
Dependencies (117)
+ 109 more |
|
v1.26.0
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.26.0
minor
Dependencies (117)
+ 109 more |
|
v1.25.0-rc0
pre
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.25.0-rc0
pre
Dependencies (123)
+ 115 more |
|
v1.25.0-dev
pre
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.25.0-dev
pre
Dependencies (126)
+ 118 more |
|
v1.23.6
patch
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.23.6
patch
Dependencies (126)
+ 118 more |
|
v1.23.5
patch
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.23.5
patch
Dependencies (126)
+ 118 more |
|
v1.23.0
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.23.0
minor
Dependencies (127)
+ 119 more |
|
v1.22.6
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.22.6
minor
Dependencies (117)
+ 109 more |
|
v1.23.0-dev
pre
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.23.0-dev
pre
Dependencies (117)
+ 109 more |
|
v1.21.8
patch
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.21.8
patch
Dependencies (119)
+ 111 more |
|
v1.21.4
patch
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.21.4
patch
Dependencies (119)
+ 111 more |
|
v1.21.3
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.21.3
minor
Dependencies (119)
+ 111 more |
|
v1.21.0-rc1
pre
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.21.0-rc1
pre
Dependencies (119)
+ 111 more |
|
v1.21.0-rc0
pre
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.21.0-rc0
pre
Dependencies (119)
+ 111 more |
|
v1.20.3
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.20.3
minor
Dependencies (120)
+ 112 more |
|
v1.21.0-dev
pre
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.21.0-dev
pre
Dependencies (120)
+ 112 more |
|
v1.19.2
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.19.2
minor
Dependencies (114)
+ 106 more |
|
v1.16.6
patch
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.16.6
patch
Dependencies (98)
+ 90 more |
|
v1.16.5
patch
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.16.5
patch
Dependencies (98)
+ 90 more |
|
v1.16.0
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.16.0
minor
Dependencies (98)
+ 90 more |
|
v1.15.8
patch
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.15.8
patch
Dependencies (96)
+ 88 more |
|
v1.15.0
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.15.0
minor
Dependencies (96)
+ 88 more |
|
v1.14.2
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.14.2
minor
Dependencies (97)
+ 89 more |
|
v1.13.7
patch
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.13.7
patch
Dependencies (96)
+ 88 more |
|
v1.14.0-rc2
pre
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.14.0-rc2
pre
Dependencies (97)
+ 89 more |
|
v1.13.5
patch
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.13.5
patch
Dependencies (96)
+ 88 more |
|
v1.14.0-rc1
pre
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.14.0-rc1
pre
Dependencies (97)
+ 89 more |
|
v1.13.4
patch
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.13.4
patch
Dependencies (96)
+ 88 more |
|
v1.13.0
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.13.0
minor
Dependencies (96)
+ 88 more |
|
v1.12.0-rc1
pre
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.12.0-rc1
pre
Dependencies (89)
+ 81 more |
|
v1.11.5
patch
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.11.5
patch
Dependencies (77)
+ 69 more |
|
v1.11.3
patch
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.11.3
patch
Dependencies (77)
+ 69 more |
|
v1.10.6
patch
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.10.6
patch
Dependencies (76)
+ 68 more |
|
v1.10.5
patch
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.10.5
patch
Dependencies (81)
+ 73 more |
|
v1.11.1
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.11.1
minor
Dependencies (77)
+ 69 more |
|
v1.10.3
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.10.3
minor
Dependencies (76)
+ 68 more |
|
v1.11.0-rc1
pre
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.11.0-rc1
pre
Dependencies (77)
+ 69 more |
|
v1.9.5
patch
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.9.5
patch
Dependencies (73)
+ 65 more |
|
v1.10.0-rc1
pre
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.10.0-rc1
pre
Dependencies (76)
+ 68 more |
|
v1.9.2
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.9.2
minor
Dependencies (72)
+ 64 more |
|
v1.8.1
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.8.1
minor
|
|
v1.7.6
patch
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.7.6
patch
|
|
v1.8.0-rc2
pre
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.8.0-rc2
pre
|
|
v1.7.4
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.7.4
minor
|
|
v1.6.2
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.6.2
minor
|
|
v1.5.3
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.5.3
minor
|
|
v1.6.0-rc1
pre
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.6.0-rc1
pre
|
|
v1.1.0
minor
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.1.0
minor
|
|
v1.0.1
major
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v1.0.1
major
|
|
v0.9.99
initial
43 CVEs
CVE-2026-58432
GO-2026-6070
GHSA-q9pg-jj6x-j9p6
Jul 27, 2026
Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Gitea: draft release attachment disclosure via missing web authorization in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58435
GO-2026-6073
GHSA-rh79-75qm-gwjr
Jul 27, 2026
Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Gitea LFS Deploy-Key Privilege Escalation in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58507
GO-2026-6066
GHSA-p4mj-98mv-xq26
Jul 27, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-56750
GO-2026-6072
GHSA-rgv6-xp99-6mgj
Jul 27, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58417
GO-2026-6063
GHSA-jr5x-6h83-wrxf
Jul 27, 2026
Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Gitea: REST API exposes organization membership of private organizations to public in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58438
GO-2026-6085
GHSA-xv9x-fj9g-vj6h
Jul 27, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58510
GO-2026-6069
GHSA-q423-49rw-g9mh
Jul 27, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55987
GO-2026-6078
GHSA-vrhc-jjfc-m3m3
Jul 27, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-23603
GO-2026-6083
GHSA-x77v-q46j-393g
Jul 27, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-59766
GO-2026-6071
GHSA-qf2f-qh6p-7v89
Jul 27, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58442
GO-2026-6058
GHSA-h2x6-g7q6-344v
Jul 27, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58425
GO-2026-6079
GHSA-vxv2-8j6r-pcpg
Jul 27, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58443
GO-2026-6086
GHSA-xxjv-752h-3vp2
Jul 27, 2026
Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Gitea: Public-only repository tokens can update private PR head branches in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58431
GO-2026-6059
GHSA-h56g-4qw7-2mxg
Jul 27, 2026
Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58434
GO-2026-6062
GHSA-j2w3-9c3r-g83q
Jul 27, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev Fixed in
1.27.0
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58445
GO-2026-6067
GHSA-pgqf-926r-548m
Jul 27, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-42931
GO-2026-6082
GHSA-wwqq-x6w4-frm2
Jul 27, 2026
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58427
GO-2026-6068
GHSA-prr9-9mp4-5gp2
Jul 27, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55982
GO-2026-6065
GHSA-mg4f-x9v4-6h2p
Jul 27, 2026
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-55984
GO-2026-6064
GHSA-m932-crvm-gcp5
Jul 27, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-58441
GO-2026-6084
GHSA-xmj7-xj85-hfc3
Jul 27, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev Fixed in
1.27.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2026-57897
GO-2026-6054
GHSA-frpw-3h2q-4jj6
Jul 22, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56654
GO-2026-6034
GHSA-683j-3ff6-hh2x
Jul 22, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58511
GO-2026-6040
GHSA-3r5c-2xxx-h872
Jul 22, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58420
GO-2026-6032
GHSA-5ggr-2f2h-jmvm
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev Fixed in
1.27.0
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58436
GO-2026-6055
GHSA-fw57-jgch-pgf3
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-54481
GO-2026-6048
GHSA-94v3-77j7-vm48
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57894
GO-2026-6027
GHSA-82f7-87hm-852x
Jul 22, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56657
GO-2026-6042
GHSA-4xjf-493q-98p3
Jul 22, 2026
Gitea SSH Key Parser Denial of Service in gitea.dev Gitea SSH Key Parser Denial of Service in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56755
GO-2026-6037
GHSA-6hm7-3pwj-22rm
Jul 22, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59763
GO-2026-6049
GHSA-9mq6-mqjj-c2c5
Jul 22, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58428
GO-2026-6028
GHSA-25gq-j9jx-43pg
Jul 22, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-50105
GO-2026-6036
GHSA-6cqf-375w-639g
Jul 22, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-57886
GO-2026-6035
GHSA-6c6r-5xr4-cr5m
Jul 22, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58437
GO-2026-6047
GHSA-8p9h-49rc-qgxj
Jul 22, 2026
Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58429
GO-2026-6053
GHSA-fq2p-5p22-8g6j
Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-56443
GO-2026-6045
GHSA-7p4h-3gxq-x3h3
Jul 22, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-59765
GO-2026-6039
GHSA-2wm4-vwp6-v7xc
Jul 22, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58314
GO-2026-6038
GHSA-2fcr-jfvc-vgg2
Jul 22, 2026
Gitea: Two SSRF findings in gitea.dev Gitea: Two SSRF findings in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58416
GO-2026-6052
GHSA-fj8v-hjwv-qm88
Jul 22, 2026
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58444
GO-2026-6050
GHSA-cp3q-vrj2-ghhh
Jul 22, 2026
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev Gitea: Personal access token scope enforcement bypass on the repository home page ( Fixed in
1.27.0
References Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-58440
GO-2026-6033
GHSA-66m4-5jjr-2rg5
Jul 22, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev Fixed in
1.27.0
References
Updated Jul 22, 2026 · Source: OSV.dev
CVE-2026-28740
GHSA-2m9v-5q2g-58vq
GO-2026-6029
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
7.1
/ 10
High
Network
High
Low
None
Changed
High
Low
None
SummaryA user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object. The issue appears to be caused by the source-object authorization check using broad repository accessibility instead of requiring Code-unit access to at least one repository that owns the requested LFS object. ImpactThis issue breaks the expected authorization boundary between repository units. A user who does not have Code access to a private source repository should not be able to reuse or associate Git LFS objects owned by that repository. However, because the source-object accessibility check accepts broad repository access, non-Code access such as Issues access may be sufficient for the LFS object to be treated as accessible. If the reused object becomes downloadable through the attacker-controlled target repository after metadata association, this can result in cross-repository Git LFS content disclosure. The target repository write authorization is still enforced. The problem is specifically in the authorization decision for whether the source LFS object is accessible and may be reused. PreconditionsThe attacker needs:
Affected AreaThe issue affects the Git LFS upload/object reuse path. Relevant paths:
Relevant handlers:
Both paths can call:
The helper is located in:
The authorization check uses:
When By contrast, Code-specific repository access checks use a concrete unit type and include ValidationI reproduced this locally using Gitea's Go test harness. Validated against commit:
The PoC creates the following scenario:
Test result:
No live instance was tested. Validation was performed only against a local test database. Security ExpectationA user should not be allowed to reuse or associate an LFS object from a private source repository unless they have Code access to that source repository, or another permission level explicitly intended to grant access to repository file contents. Non-Code permissions such as Issues access should not authorize access to Git LFS object content or allow Git LFS object reuse. Suggested Fix
The check should avoid using A regression test should cover:
Suggested SeveritySuggested severity: Medium to High. The severity depends on whether the associated LFS object becomes downloadable through the target repository after reuse. If the object becomes downloadable through the target repository, the issue should be considered High because it can lead to cross-repository Git LFS content disclosure. Suggested CVSS v3.1 if content disclosure is confirmed:
Rationale:
EvidenceI can provide the local regression test and passing test log privately if needed. Fixed in
1.26.3
References
Updated Jul 22, 2026 · Source: OSV.dev |
v0.9.99
initial
|