Vulnerabilities in Gitea

112 results
Vexday analysis

Gitea apresenta perfil de risco moderado com 63 vulnerabilidades catalogadas, sendo 16 críticas (CVSS≥9) e 41 publicadas nos últimos 90 dias, indicando exposição a descobertas recentes. Apesar da ausência de exploração ativa registrada (KEV=0), a fraqueza dominante CWE-284 (controle de acesso inadequado) representa vetor de risco estrutural que demanda revisão de permissões e segmentação. A velocidade de publicação de vulnerabilidades sugere monitoramento contínuo de patches.

CVE-2026-58433CRITICALTeam-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization settingEPSS 0.3%CVE-2026-58434HIGHPrivate Repository Metadata Remains Accessible After Access RevocationEPSS 0.3%CVE-2026-58440MEDIUMWebhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)EPSS 0.3%CVE-2025-68944MEDIUMGitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.EPSS 0.3%CVE-2025-68940LOWIn Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.EPSS 0.3%CVE-2026-58438HIGHCross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot accessEPSS 0.3%CVE-2026-0798LOWGitea Release Email Notifications Leak Private Repository Release Details After Access RevocationEPSS 0.3%CVE-2026-58432MEDIUMMissing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/giteaEPSS 0.3%CVE-2026-58508CRITICALTwo SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)EPSS 0.3%CVE-2026-57894HIGHRepository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository ExfiltrationEPSS 0.3%CVE-2026-58425MEDIUMOAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)EPSS 0.3%CVE-2025-68941MEDIUMGitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.EPSS 0.3%CVE-2026-58507MEDIUMPrivate Repository Existence Disclosure via go-get Meta EndpointEPSS 0.3%CVE-2026-55986MEDIUMEmail Management API Bypasses ManageCredentials Feature RestrictionsEPSS 0.3%CVE-2026-58416HIGHFork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)EPSS 0.3%CVE-2026-57886MEDIUMCross-repository issue/comment attachment re-linking can expose private attachment contentEPSS 0.3%CVE-2026-24791HIGHPublic-only tokens bypass private-resource restrictions on `/api/v1/user` self routesEPSS 0.3%CVE-2026-23603LOWBlind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claimEPSS 0.2%CVE-2025-68946MEDIUMIn Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.EPSS 0.2%CVE-2025-68942MEDIUMGitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.EPSS 0.2%