Gitea Vulnerabilities and Affected Products
Vulnerabilities associated with Gitea Open Source Git Server.
Products
Clear product- Gitea Open Source Git Server97 vulnerabilities
- Gitea14 vulnerabilities
- act_runner1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Gitea runner registration-token GET endpoint performs a write under a read-only token scopeThe GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked read:user-scoped token can therefore mint a registration token and register a malicious Actions runner that executes workflow jobs with access to repository secrets and source code. CWE-269Aug 13, 2026 | CVSS- | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-24791HIGH | Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routesPublic-only tokens bypass private-resource restrictions on `/api/v1/user` self routes CWE-863Aug 13, 2026 | CVSS8.1v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud MetadataSSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata CWE-918Aug 13, 2026 | CVSS-v4.0 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Unbounded Arch package file metadata can cause resource amplification in Gitea package uploadsUnbounded Arch package file metadata can cause resource amplification in Gitea package uploads | CVSS-v4.0 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Webhook Authorization Header Returned in Plaintext via APIWebhook Authorization Header Returned in Plaintext via API CWE-200Aug 13, 2026 | CVSS2.7v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-58510MEDIUM | GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->privateGHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private | CVSS4.3v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) CWE-284Aug 13, 2026 | CVSS- | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Private Repository Existence Disclosure via go-get Meta EndpointPrivate Repository Existence Disclosure via go-get Meta Endpoint | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel APICross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contentsPersonal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents CWE-863Aug 13, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Public-only repository tokens can update private PR head branchesPublic-only repository tokens can update private PR head branches CWE-863Aug 13, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Repository migration SSRF via multi-answer DNS allow-list bypassRepository migration SSRF via multi-answer DNS allow-list bypass | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURLSSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL CWE-918Aug 13, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`) | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval FlagBranch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot accessCross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access CWE-862Aug 13, 2026 | CVSS-v4.0 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Repository Visibility Manipulation via Git Push OptionsRepository Visibility Manipulation via Git Push Options CWE-284Aug 13, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requestsParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests | CVSS-v4.0 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Gitea LFS Deploy-Key Privilege EscalationGitea LFS Deploy-Key Privilege Escalation | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Private Repository Metadata Remains Accessible After Access RevocationPrivate Repository Metadata Remains Accessible After Access Revocation | CVSS-v4.0 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization settingTeam-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting CWE-862Aug 13, 2026 | CVSS- | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/giteaMissing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Public-only API token restriction is not enforced on team API routesPublic-only API token restriction is not enforced on team API routes CWE-863Aug 13, 2026 | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Public-Only Personal access tokens scope bypass in Organization and Permission EndpointsPublic-Only Personal access tokens scope bypass in Organization and Permission Endpoints | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |