Showing 8 vulnerabilities on this page for gitea.dev

Signals CISA KEV Ransomware Nuclei
Go vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)

Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)

CWE-284CWE-863Aug 13, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access

Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access

CWE-862Aug 13, 2026
CVSS-v4.0EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Public-only API token restriction is not enforced on team API routes

Public-only API token restriction is not enforced on team API routes

CWE-863Aug 13, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

CWE-200CWE-863Aug 13, 2026
CVSS-EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Local File Inclusion via file:// URI in Migration Restore

Local File Inclusion via file:// URI in Migration Restore

CWE-284CWE-73Aug 13, 2026
CVSS-v4.0EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

REST API exposes organization membership of private organizations to public

REST API exposes organization membership of private organizations to public

CVSS-v4.0EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

CWE-280CWE-863Aug 13, 2026
CVSS7.1v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Gitea LFS object reuse bypasses Code-unit authorization

Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.

CWE-639CWE-863Jul 3, 2026
CVSS7.1v3.1EPSS0.267%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX