Technology · Go
code.gitea.io/gitea (Go) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 76 vulnerabilities in code.gitea.io/gitea (Go): 0 in the last 7 days and 74 in the last 90 days, 11 of them critical and 0 exploited in the wild. The most recent, CVE-2026-58429, was published on 21 July 2026.
- Last 7 days
- 0
- Last 90 days
- 74
- Critical, all time
- 11
- Exploited in the wild
- 0
About code.gitea.io/gitea (Go)
A self-hosted Git service written in Go, providing repository management and collaboration tools.
Latest code.gitea.io/gitea (Go) vulnerabilities
- CVE-2026-58429: Gitea public-only token scope bypass in Organization and Permission endpointsmediumCVSS 4.9
- CVE-2026-59765: Gitea SSRF and local file read via migration asset bypassmediumCVSS 6.9
- CVE-2026-58511: Gitea plaintext webhook authorization header exposure in APIlowCVSS 2.7
- CVE-2026-57897: Gitea information disclosure in organization Actions APImediumCVSS 6.5
- CVE-2026-58510: Gitea information disclosure via stale watches in REST APImediumCVSS 4.3
- CVE-2026-58314: Gitea SSRF in webhooks and OpenID discoveryhighCVSS 7.7
- CVE-2026-58436: Gitea quadratic-time DoS in Locale middleware via Accept-Language headerhighCVSS 7.5
- CVE-2026-56657: Gitea SSH key parser denial of service in normalization loopmediumCVSS 6.5
- CVE-2026-58437: Gitea repository visibility manipulation via Git push optionshighCVSS 7.1
- CVE-2026-55987: Gitea account deactivation bypass via OAuth2 sign-inhighCVSS 8.1
- CVE-2026-58435: Gitea LFS privilege escalation via deploy key impersonationmediumCVSS 5.4
- CVE-2026-55984: Gitea NULL pointer dereference in AddTime APIlowCVSS 2.7
- CVE-2026-55982: Gitea OIDC userinfo scope bypass allows identity disclosuremediumCVSS 5.3
- CVE-2026-58434: Gitea information disclosure via starred repository metadata after access revocationlowCVSS 2.3
- CVE-2026-54481: Gitea improper certificate validation in internal API clienthighCVSS 7.5
- CVE-2026-50105: Gitea authorization bypass in RSS and Atom feed handlersmediumCVSS 4.3
- CVE-2026-42931: Gitea denial of service via unbounded memory allocation in NPM APImediumCVSS 6.5
- CVE-2026-58445: Gitea cross-repository label enumeration oracle in DeleteIssueLabel APIlowCVSS 2.7
- CVE-2026-58444: Gitea token scope bypass in repository home pagemediumCVSS 4.3
- CVE-2026-58443: Gitea public-only token scope bypass in pull request updatescriticalCVSS 9.6
- CVE-2026-58442: Gitea SSRF via multi-answer DNS allow-list bypass in repository migrationmediumCVSS 6.5
- CVE-2026-58441: Gitea SSRF in restore-repo via unsanitized Head.CloneURLmediumCVSS 6.3
- Gitea auth bypass in API fork endpointmediumCVSS 5.3
- CVE-2026-56654: Gitea privilege escalation via access token scope escalation in APIhighCVSS 8.8
- CVE-2026-56755: Gitea DoS via resource exhaustion in Debian package uploadhighCVSS 7.5
Most severe code.gitea.io/gitea (Go) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-20896: Gitea Docker image authentication bypass via trusted proxy misconfigurationcriticalCVSS 9.8EPSS 0.8%
- CVE-2026-26292: Gitea migration transport bypass in LFS mirror operationscriticalCVSS 9.8EPSS 0.7%
- CVE-2026-27780: Gitea branch protection bypass via bufio.Scanner error handling in pre-receive hookscriticalCVSS 9.8EPSS 0.6%
- CVE-2026-22874: Gitea SSRF via incomplete hostmatcher allow-list filteringcriticalCVSS 9.6EPSS 0.5%
- CVE-2026-58426: Gitea Actions HMAC ambiguity in Artifacts V4 signed URLscriticalCVSS 9.6EPSS 0.2%
- CVE-2026-58443: Gitea public-only token scope bypass in pull request updatescriticalCVSS 9.6
- CVE-2026-25718: Gitea improper link resolution in template repository generationcriticalCVSS 9.1EPSS 0.6%
- CVE-2026-22547: Gitea improper input validation in repository creation fieldscriticalCVSS 9.1EPSS 0.5%
- CVE-2026-26247: Gitea OAuth2 PKCE S256 verifier bypasscriticalCVSS 9.1EPSS 0.5%
- CVE-2026-26232: Gitea OAuth2 authorization code reuse and expiry vulnerabilitycriticalCVSS 9.1EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 38 | 9 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 36 | 2 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/code-gitea-io-gitea.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "code.gitea.io/gitea (Go) vulnerabilities", https://junglewise.ai/threats/technologies/code-gitea-io-gitea, 26 September 2026.