github.com/go-gitea/gitea
Git with a cup of tea! Painless self-hosted all-in-one software development service, including Git hosting, code review, team collaboration, package registry and CI/CD
Activity
- Latest release
- May 20, 2026
- Total releases
- 50
- Cadence
- ~35 days
- Last 12 months
- 3
Reach
- Stars
- 57.2k
Details
- First release
- Oct 17, 2016
| Version | Released | |
|---|---|---|
v1.26.2
patch
|
v1.26.2
patch
Dependencies (117)
+ 109 more |
|
v1.26.0
minor
|
v1.26.0
minor
Dependencies (117)
+ 109 more |
|
v1.25.0-rc0
pre
8 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev |
v1.25.0-rc0
pre
Dependencies (123)
+ 115 more |
|
v1.25.0-dev
pre
8 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev |
v1.25.0-dev
pre
Dependencies (126)
+ 118 more |
|
v1.23.6
patch
8 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev |
v1.23.6
patch
Dependencies (126)
+ 118 more |
|
v1.23.5
patch
8 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev |
v1.23.5
patch
Dependencies (126)
+ 118 more |
|
v1.23.0
minor
8 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev |
v1.23.0
minor
Dependencies (127)
+ 119 more |
|
v1.22.6
minor
8 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev |
v1.22.6
minor
Dependencies (117)
+ 109 more |
|
v1.23.0-dev
pre
8 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev |
v1.23.0-dev
pre
Dependencies (118)
+ 110 more |
|
v1.21.8
patch
8 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev |
v1.21.8
patch
Dependencies (119)
+ 111 more |
|
v1.21.4
patch
8 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev |
v1.21.4
patch
Dependencies (119)
+ 111 more |
|
v1.21.3
minor
8 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev |
v1.21.3
minor
Dependencies (119)
+ 111 more |
|
v1.21.0-rc1
pre
8 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev |
v1.21.0-rc1
pre
Dependencies (119)
+ 111 more |
|
v1.21.0-rc0
pre
8 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev |
v1.21.0-rc0
pre
Dependencies (119)
+ 111 more |
|
v1.20.3
minor
8 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev |
v1.20.3
minor
Dependencies (120)
+ 112 more |
|
v1.21.0-dev
pre
8 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev |
v1.21.0-dev
pre
Dependencies (120)
+ 112 more |
|
v1.19.2
minor
8 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev |
v1.19.2
minor
Dependencies (114)
+ 106 more |
|
v1.16.6
patch
9 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev |
v1.16.6
patch
Dependencies (98)
+ 90 more |
|
v1.16.5
patch
9 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev |
v1.16.5
patch
Dependencies (98)
+ 90 more |
|
v1.16.0
minor
9 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev |
v1.16.0
minor
Dependencies (98)
+ 90 more |
|
v1.15.8
patch
9 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev |
v1.15.8
patch
Dependencies (96)
+ 88 more |
|
v1.15.0
minor
9 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev |
v1.15.0
minor
Dependencies (96)
+ 88 more |
|
v1.14.2
minor
9 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev |
v1.14.2
minor
Dependencies (97)
+ 89 more |
|
v1.13.7
patch
9 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev |
v1.13.7
patch
Dependencies (96)
+ 88 more |
|
v1.14.0-rc2
pre
9 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev |
v1.14.0-rc2
pre
Dependencies (97)
+ 89 more |
|
v1.13.5
patch
9 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev |
v1.13.5
patch
Dependencies (96)
+ 88 more |
|
v1.14.0-rc1
pre
9 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev |
v1.14.0-rc1
pre
Dependencies (97)
+ 89 more |
|
v1.13.4
patch
9 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev |
v1.13.4
patch
Dependencies (96)
+ 88 more |
|
v1.13.0
minor
10 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2021-3382
GHSA-9f8c-pfvv-p4gm
BIT-gitea-2021-3382
GO-2024-2757
Apr 24, 2024
Buffer Overflow in gitea
7.0
/ 10
High
Network
High
None
None
Unchanged
Low
Low
High
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path. Fixed in
1.13.2
References Updated Jun 04, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev |
v1.13.0
minor
Dependencies (96)
+ 88 more |
|
v1.12.0-rc1
pre
12 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2021-3382
GHSA-9f8c-pfvv-p4gm
BIT-gitea-2021-3382
GO-2024-2757
Apr 24, 2024
Buffer Overflow in gitea
7.0
/ 10
High
Network
High
None
None
Unchanged
Low
Low
High
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path. Fixed in
1.13.2
References Updated Jun 04, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev |
v1.12.0-rc1
pre
Dependencies (89)
+ 81 more |
|
v1.11.5
patch
12 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2021-3382
GHSA-9f8c-pfvv-p4gm
BIT-gitea-2021-3382
GO-2024-2757
Apr 24, 2024
Buffer Overflow in gitea
7.0
/ 10
High
Network
High
None
None
Unchanged
Low
Low
High
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path. Fixed in
1.13.2
References Updated Jun 04, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev |
v1.11.5
patch
Dependencies (77)
+ 69 more |
|
v1.11.3
patch
12 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2021-3382
GHSA-9f8c-pfvv-p4gm
BIT-gitea-2021-3382
GO-2024-2757
Apr 24, 2024
Buffer Overflow in gitea
7.0
/ 10
High
Network
High
None
None
Unchanged
Low
Low
High
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path. Fixed in
1.13.2
References Updated Jun 04, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev |
v1.11.3
patch
Dependencies (77)
+ 69 more |
|
v1.10.6
patch
13 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2021-3382
GHSA-9f8c-pfvv-p4gm
BIT-gitea-2021-3382
GO-2024-2757
Apr 24, 2024
Buffer Overflow in gitea
7.0
/ 10
High
Network
High
None
None
Unchanged
Low
Low
High
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path. Fixed in
1.13.2
References Updated Jun 04, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v1.10.6
patch
Dependencies (76)
+ 68 more |
|
v1.10.5
patch
13 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2021-3382
GHSA-9f8c-pfvv-p4gm
BIT-gitea-2021-3382
GO-2024-2757
Apr 24, 2024
Buffer Overflow in gitea
7.0
/ 10
High
Network
High
None
None
Unchanged
Low
Low
High
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path. Fixed in
1.13.2
References Updated Jun 04, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v1.10.5
patch
Dependencies (76)
+ 68 more |
|
v1.11.1
minor
13 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2021-3382
GHSA-9f8c-pfvv-p4gm
BIT-gitea-2021-3382
GO-2024-2757
Apr 24, 2024
Buffer Overflow in gitea
7.0
/ 10
High
Network
High
None
None
Unchanged
Low
Low
High
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path. Fixed in
1.13.2
References Updated Jun 04, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v1.11.1
minor
Dependencies (77)
+ 69 more |
|
v1.10.3
minor
13 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2021-3382
GHSA-9f8c-pfvv-p4gm
BIT-gitea-2021-3382
GO-2024-2757
Apr 24, 2024
Buffer Overflow in gitea
7.0
/ 10
High
Network
High
None
None
Unchanged
Low
Low
High
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path. Fixed in
1.13.2
References Updated Jun 04, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v1.10.3
minor
Dependencies (76)
+ 68 more |
|
v1.11.0-rc1
pre
13 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2021-3382
GHSA-9f8c-pfvv-p4gm
BIT-gitea-2021-3382
GO-2024-2757
Apr 24, 2024
Buffer Overflow in gitea
7.0
/ 10
High
Network
High
None
None
Unchanged
Low
Low
High
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path. Fixed in
1.13.2
References Updated Jun 04, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v1.11.0-rc1
pre
Dependencies (77)
+ 69 more |
|
v1.9.5
patch
13 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2021-3382
GHSA-9f8c-pfvv-p4gm
BIT-gitea-2021-3382
GO-2024-2757
Apr 24, 2024
Buffer Overflow in gitea
7.0
/ 10
High
Network
High
None
None
Unchanged
Low
Low
High
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path. Fixed in
1.13.2
References Updated Jun 04, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v1.9.5
patch
Dependencies (73)
+ 65 more |
|
v1.10.0-rc1
pre
13 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2021-3382
GHSA-9f8c-pfvv-p4gm
BIT-gitea-2021-3382
GO-2024-2757
Apr 24, 2024
Buffer Overflow in gitea
7.0
/ 10
High
Network
High
None
None
Unchanged
Low
Low
High
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path. Fixed in
1.13.2
References Updated Jun 04, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v1.10.0-rc1
pre
Dependencies (76)
+ 68 more |
|
v1.9.2
minor
13 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2021-3382
GHSA-9f8c-pfvv-p4gm
BIT-gitea-2021-3382
GO-2024-2757
Apr 24, 2024
Buffer Overflow in gitea
7.0
/ 10
High
Network
High
None
None
Unchanged
Low
Low
High
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path. Fixed in
1.13.2
References Updated Jun 04, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v1.9.2
minor
Dependencies (72)
+ 64 more |
|
v1.8.1
minor
12 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v1.8.1
minor
|
|
v1.7.6
patch
12 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v1.7.6
patch
|
|
v1.8.0-rc2
pre
12 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v1.8.0-rc2
pre
|
|
v1.7.4
minor
14 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2019-11228
GO-2022-0862
GHSA-q47x-6mqq-4w92
Aug 21, 2024
Gitea Improper Input Validation in github.com/go-gitea/gitea Gitea Improper Input Validation in github.com/go-gitea/gitea Fixed in
1.7.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-11229
GO-2022-0846
GHSA-hpmr-prr2-cqc4
Aug 21, 2024
Gitea Remote Code Execution in github.com/go-gitea/gitea Gitea Remote Code Execution in github.com/go-gitea/gitea Fixed in
1.7.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v1.7.4
minor
|
|
v1.6.2
minor
15 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2019-11228
GO-2022-0862
GHSA-q47x-6mqq-4w92
Aug 21, 2024
Gitea Improper Input Validation in github.com/go-gitea/gitea Gitea Improper Input Validation in github.com/go-gitea/gitea Fixed in
1.7.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-11229
GO-2022-0846
GHSA-hpmr-prr2-cqc4
Aug 21, 2024
Gitea Remote Code Execution in github.com/go-gitea/gitea Gitea Remote Code Execution in github.com/go-gitea/gitea Fixed in
1.7.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-45325
GO-2022-0308
BIT-gitea-2021-45325
GHSA-8h8p-x289-vvqr
Aug 21, 2024
Gitea displaying raw OpenID error in UI in github.com/go-gitea/gitea Gitea displaying raw OpenID error in UI in github.com/go-gitea/gitea Fixed in
1.7.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v1.6.2
minor
|
|
v1.5.3
minor
15 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2019-11228
GO-2022-0862
GHSA-q47x-6mqq-4w92
Aug 21, 2024
Gitea Improper Input Validation in github.com/go-gitea/gitea Gitea Improper Input Validation in github.com/go-gitea/gitea Fixed in
1.7.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-11229
GO-2022-0846
GHSA-hpmr-prr2-cqc4
Aug 21, 2024
Gitea Remote Code Execution in github.com/go-gitea/gitea Gitea Remote Code Execution in github.com/go-gitea/gitea Fixed in
1.7.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-45325
GO-2022-0308
BIT-gitea-2021-45325
GHSA-8h8p-x289-vvqr
Aug 21, 2024
Gitea displaying raw OpenID error in UI in github.com/go-gitea/gitea Gitea displaying raw OpenID error in UI in github.com/go-gitea/gitea Fixed in
1.7.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v1.5.3
minor
|
|
v1.6.0-rc1
pre
15 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2019-11228
GO-2022-0862
GHSA-q47x-6mqq-4w92
Aug 21, 2024
Gitea Improper Input Validation in github.com/go-gitea/gitea Gitea Improper Input Validation in github.com/go-gitea/gitea Fixed in
1.7.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-11229
GO-2022-0846
GHSA-hpmr-prr2-cqc4
Aug 21, 2024
Gitea Remote Code Execution in github.com/go-gitea/gitea Gitea Remote Code Execution in github.com/go-gitea/gitea Fixed in
1.7.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-45325
GO-2022-0308
BIT-gitea-2021-45325
GHSA-8h8p-x289-vvqr
Aug 21, 2024
Gitea displaying raw OpenID error in UI in github.com/go-gitea/gitea Gitea displaying raw OpenID error in UI in github.com/go-gitea/gitea Fixed in
1.7.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v1.6.0-rc1
pre
|
|
v1.1.0
minor
19 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2019-11228
GO-2022-0862
GHSA-q47x-6mqq-4w92
Aug 21, 2024
Gitea Improper Input Validation in github.com/go-gitea/gitea Gitea Improper Input Validation in github.com/go-gitea/gitea Fixed in
1.7.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-11229
GO-2022-0846
GHSA-hpmr-prr2-cqc4
Aug 21, 2024
Gitea Remote Code Execution in github.com/go-gitea/gitea Gitea Remote Code Execution in github.com/go-gitea/gitea Fixed in
1.7.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-1000803
GO-2022-0823
GHSA-f5fj-7265-jxhj
Aug 21, 2024
Gitea Exposes Private Email Addresses in github.com/go-gitea/gitea Gitea Exposes Private Email Addresses in github.com/go-gitea/gitea Fixed in
1.5.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-45328
GO-2022-0579
BIT-gitea-2021-45328
GHSA-36h2-95gj-w488
Aug 21, 2024
Open redirect in Gitea in github.com/go-gitea/gitea Open redirect in Gitea in github.com/go-gitea/gitea Fixed in
1.4.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-45329
GO-2022-0314
BIT-gitea-2021-45329
GHSA-r3gq-wxqf-q4gh
Aug 21, 2024
Cross-site Scripting in Gitea in github.com/go-gitea/gitea Cross-site Scripting in Gitea in github.com/go-gitea/gitea Fixed in
1.5.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-45325
GO-2022-0308
BIT-gitea-2021-45325
GHSA-8h8p-x289-vvqr
Aug 21, 2024
Gitea displaying raw OpenID error in UI in github.com/go-gitea/gitea Gitea displaying raw OpenID error in UI in github.com/go-gitea/gitea Fixed in
1.7.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-45326
GO-2022-0309
BIT-gitea-2021-45326
GHSA-4wp3-8q92-mh8w
Aug 21, 2024
Cross Site Request Forgery in Gitea in github.com/go-gitea/gitea Cross Site Request Forgery in Gitea in github.com/go-gitea/gitea Fixed in
1.5.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v1.1.0
minor
|
|
v1.0.1
major
19 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2019-11228
GO-2022-0862
GHSA-q47x-6mqq-4w92
Aug 21, 2024
Gitea Improper Input Validation in github.com/go-gitea/gitea Gitea Improper Input Validation in github.com/go-gitea/gitea Fixed in
1.7.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-11229
GO-2022-0846
GHSA-hpmr-prr2-cqc4
Aug 21, 2024
Gitea Remote Code Execution in github.com/go-gitea/gitea Gitea Remote Code Execution in github.com/go-gitea/gitea Fixed in
1.7.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-1000803
GO-2022-0823
GHSA-f5fj-7265-jxhj
Aug 21, 2024
Gitea Exposes Private Email Addresses in github.com/go-gitea/gitea Gitea Exposes Private Email Addresses in github.com/go-gitea/gitea Fixed in
1.5.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-45328
GO-2022-0579
BIT-gitea-2021-45328
GHSA-36h2-95gj-w488
Aug 21, 2024
Open redirect in Gitea in github.com/go-gitea/gitea Open redirect in Gitea in github.com/go-gitea/gitea Fixed in
1.4.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-45329
GO-2022-0314
BIT-gitea-2021-45329
GHSA-r3gq-wxqf-q4gh
Aug 21, 2024
Cross-site Scripting in Gitea in github.com/go-gitea/gitea Cross-site Scripting in Gitea in github.com/go-gitea/gitea Fixed in
1.5.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-45325
GO-2022-0308
BIT-gitea-2021-45325
GHSA-8h8p-x289-vvqr
Aug 21, 2024
Gitea displaying raw OpenID error in UI in github.com/go-gitea/gitea Gitea displaying raw OpenID error in UI in github.com/go-gitea/gitea Fixed in
1.7.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-45326
GO-2022-0309
BIT-gitea-2021-45326
GHSA-4wp3-8q92-mh8w
Aug 21, 2024
Cross Site Request Forgery in Gitea in github.com/go-gitea/gitea Cross Site Request Forgery in Gitea in github.com/go-gitea/gitea Fixed in
1.5.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v1.0.1
major
|
|
v0.9.99
initial
19 CVEs
CVE-2026-25779
GHSA-j5r2-4c8j-xc3m
GO-2026-5448
Jun 17, 2026
Gitea: Open Redirect via redirect_to
Medium
Network
Low
None
DetailsDespite the validation within PoCWhen a user uses this URL to login:
They would be redirected to Impact
Fixed in
1.26.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-20904
GHSA-qqgv-v353-cv8p
BIT-gitea-2026-20904
GHSA-jrpc-w85r-hgqx
GO-2026-4369
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Medium
Network
Low
Low
None
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20912
GHSA-4xx9-vc8v-87hv
BIT-gitea-2026-20912
GHSA-vfmv-f93v-37mw
GO-2026-4364
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Medium
Network
Low
Low
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20888
GHSA-9cgq-wp42-4rpq
BIT-gitea-2026-20888
GHSA-ccq9-c5hv-cf64
GO-2026-4366
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Medium
Network
Low
Low
None
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20883
GHSA-j8xr-c56q-m8jj
BIT-gitea-2026-20883
GHSA-644v-xv3j-xgqg
GO-2026-4368
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
Network
Low
Low
None
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20897
GHSA-393c-qgvj-3xph
BIT-gitea-2026-20897
GHSA-rrq5-r9h5-pc7c
GO-2026-4363
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Medium
Network
Low
Low
None
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20750
GHSA-rw22-5hhq-pfpf
BIT-gitea-2026-20750
GHSA-h4fh-pc4w-8w27
GO-2026-4370
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Medium
Network
Low
Low
None
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. Fixed in
1.25.4
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-20800
GHSA-2vgv-hgv4-22mh
BIT-gitea-2026-20800
GHSA-g54m-9f6g-wj7q
GO-2026-4362
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
Network
Low
Low
None
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. Fixed in
1.25.4
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2019-11228
GO-2022-0862
GHSA-q47x-6mqq-4w92
Aug 21, 2024
Gitea Improper Input Validation in github.com/go-gitea/gitea Gitea Improper Input Validation in github.com/go-gitea/gitea Fixed in
1.7.6
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2019-11229
GO-2022-0846
GHSA-hpmr-prr2-cqc4
Aug 21, 2024
Gitea Remote Code Execution in github.com/go-gitea/gitea Gitea Remote Code Execution in github.com/go-gitea/gitea Fixed in
1.7.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-1000803
GO-2022-0823
GHSA-f5fj-7265-jxhj
Aug 21, 2024
Gitea Exposes Private Email Addresses in github.com/go-gitea/gitea Gitea Exposes Private Email Addresses in github.com/go-gitea/gitea Fixed in
1.5.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-45328
GO-2022-0579
BIT-gitea-2021-45328
GHSA-36h2-95gj-w488
Aug 21, 2024
Open redirect in Gitea in github.com/go-gitea/gitea Open redirect in Gitea in github.com/go-gitea/gitea Fixed in
1.4.3
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-45329
GO-2022-0314
BIT-gitea-2021-45329
GHSA-r3gq-wxqf-q4gh
Aug 21, 2024
Cross-site Scripting in Gitea in github.com/go-gitea/gitea Cross-site Scripting in Gitea in github.com/go-gitea/gitea Fixed in
1.5.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-45325
GO-2022-0308
BIT-gitea-2021-45325
GHSA-8h8p-x289-vvqr
Aug 21, 2024
Gitea displaying raw OpenID error in UI in github.com/go-gitea/gitea Gitea displaying raw OpenID error in UI in github.com/go-gitea/gitea Fixed in
1.7.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-45326
GO-2022-0309
BIT-gitea-2021-45326
GHSA-4wp3-8q92-mh8w
Aug 21, 2024
Cross Site Request Forgery in Gitea in github.com/go-gitea/gitea Cross Site Request Forgery in Gitea in github.com/go-gitea/gitea Fixed in
1.5.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-28991
GHSA-r7h7-chh4-5rvm
BIT-gitea-2020-28991
Apr 24, 2024
Improper Access Control in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go. Fixed in
1.12.6
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2022-42968
GHSA-w8xw-7crf-h23x
BIT-gitea-2022-42968
GO-2022-1065
Oct 16, 2022
Gitea vulnerable to Argument Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Fixed in
1.17.3
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2020-13246
GHSA-g2qx-6ghw-67hm
BIT-gitea-2020-13246
GO-2022-0830
Feb 15, 2022
Denial of Service in Gitea
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue was discovered in Gitea in which an attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another. Fixed in
1.12.0
References Updated Aug 21, 2024 · Source: OSV.dev
CVE-2021-45327
GHSA-jrpg-35hw-m4p9
BIT-gitea-2021-45327
GO-2022-0310
Feb 09, 2022
Capture-replay in Gitea
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Gitea is a project to help users set up a self-hosted Git service. Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. This could allow a remote malicious user to execute arbitrary code. Fixed in
1.11.2
References
Updated Aug 21, 2024 · Source: OSV.dev |
v0.9.99
initial
|