{"schema_version":1,"title":"code.gitea.io/gitea (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 128 vulnerabilities in code.gitea.io/gitea (Go): 0 in the last 7 days and 81 in the last 90 days, 15 of them critical and 1 exploited in the wild. The most recent, CVE-2026-60004, was published on 26 August 2026.","url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea","json_url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/code-gitea-io-gitea","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":33,"all_time":128,"critical":15,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":81,"last_365_days":104},"latest":[{"cve":"CVE-2026-60004","cvss":9.8,"epss":0.2399,"slug":"cve-2026-60004-gitea-code-injection-in-diffpatch-api","title":"Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.","severity":"critical","exploited":true,"published_at":"2026-08-26T20:17:56.01+00:00","url":"https://junglewise.ai/threats/cve-2026-60004-gitea-code-injection-in-diffpatch-api"},{"slug":"go-2026-6074-gitea-api-fork-endpoint-authorization-bypass-allows-a93de534","title":"GO-2026-6074 - Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea","severity":"info","exploited":false,"published_at":"2026-07-27T15:32:45+00:00","url":"https://junglewise.ai/threats/go-2026-6074-gitea-api-fork-endpoint-authorization-bypass-allows-a93de534"},{"cve":"CVE-2026-34966","cvss":3.1,"epss":0.0039,"slug":"cve-2026-34966-gitea-ssrf-via-migration-asset-downloads-bypasses-hostmatcher","title":"GO-2026-6039 - Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher , Reads Internal Files and Cloud Metadata in gitea.dev","severity":"low","exploited":false,"published_at":"2026-07-22T20:36:35+00:00","url":"https://junglewise.ai/threats/cve-2026-34966-gitea-ssrf-via-migration-asset-downloads-bypasses-hostmatcher"},{"cve":"CVE-2026-58429","cvss":4.9,"epss":0.0047,"slug":"cve-2026-58429-gitea-public-only-token-scope-bypass-in-organization-and","title":"Gitea public-only token scope bypass in Organization and Permission endpoints","severity":"medium","exploited":false,"published_at":"2026-07-21T21:56:04+00:00","url":"https://junglewise.ai/threats/cve-2026-58429-gitea-public-only-token-scope-bypass-in-organization-and"},{"cve":"CVE-2026-59765","cvss":6.9,"slug":"cve-2026-59765-gitea-ssrf-and-local-file-read-via-migration-asset-bypass","title":"Gitea SSRF and local file read via migration asset bypass","severity":"medium","exploited":false,"published_at":"2026-07-21T21:55:31+00:00","url":"https://junglewise.ai/threats/cve-2026-59765-gitea-ssrf-and-local-file-read-via-migration-asset-bypass"},{"cve":"CVE-2026-58511","cvss":3.1,"epss":0.0039,"slug":"cve-2026-58511-gitea-plaintext-webhook-authorization-header-exposure-in-api","title":"Gitea plaintext webhook authorization header exposure in API","severity":"low","exploited":false,"published_at":"2026-07-21T21:52:49+00:00","url":"https://junglewise.ai/threats/cve-2026-58511-gitea-plaintext-webhook-authorization-header-exposure-in-api"},{"cve":"CVE-2026-57897","cvss":6.5,"epss":0.0041,"slug":"cve-2026-57897-gitea-information-disclosure-in-organization-actions-api","title":"Gitea information disclosure in organization Actions API","severity":"medium","exploited":false,"published_at":"2026-07-21T21:52:02+00:00","url":"https://junglewise.ai/threats/cve-2026-57897-gitea-information-disclosure-in-organization-actions-api"},{"cve":"CVE-2026-58510","cvss":4.3,"epss":0.0033,"slug":"cve-2026-58510-gitea-information-disclosure-via-stale-watches-in-rest-api","title":"Gitea information disclosure via stale watches in REST API","severity":"medium","exploited":false,"published_at":"2026-07-21T21:51:41+00:00","url":"https://junglewise.ai/threats/cve-2026-58510-gitea-information-disclosure-via-stale-watches-in-rest-api"},{"cve":"CVE-2026-58314","cvss":7.7,"epss":0.004,"slug":"cve-2026-58314-gitea-ssrf-in-webhooks-and-openid-discovery","title":"Gitea SSRF in webhooks and OpenID discovery","severity":"high","exploited":false,"published_at":"2026-07-21T21:16:00+00:00","url":"https://junglewise.ai/threats/cve-2026-58314-gitea-ssrf-in-webhooks-and-openid-discovery"},{"cve":"CVE-2026-58436","cvss":4,"epss":0.0061,"slug":"cve-2026-58436-gitea-quadratic-time-dos-in-locale-middleware-via-accept-language","title":"Gitea quadratic-time DoS in Locale middleware via Accept-Language header","severity":"high","exploited":false,"published_at":"2026-07-21T21:15:47+00:00","url":"https://junglewise.ai/threats/cve-2026-58436-gitea-quadratic-time-dos-in-locale-middleware-via-accept-language"},{"cve":"CVE-2026-56657","cvss":3.1,"epss":0.0017,"slug":"cve-2026-56657-gitea-ssh-key-parser-denial-of-service-in-normalization-loop","title":"Gitea SSH key parser denial of service in normalization loop","severity":"medium","exploited":false,"published_at":"2026-07-21T21:09:57+00:00","url":"https://junglewise.ai/threats/cve-2026-56657-gitea-ssh-key-parser-denial-of-service-in-normalization-loop"},{"cve":"CVE-2026-58437","cvss":7.1,"epss":0.0034,"slug":"cve-2026-58437-gitea-repository-visibility-manipulation-via-git-push-options","title":"Gitea repository visibility manipulation via Git push options","severity":"high","exploited":false,"published_at":"2026-07-21T21:02:44+00:00","url":"https://junglewise.ai/threats/cve-2026-58437-gitea-repository-visibility-manipulation-via-git-push-options"},{"cve":"CVE-2026-55987","cvss":8.1,"epss":0.0041,"slug":"cve-2026-55987-gitea-account-deactivation-bypass-via-oauth2-sign-in","title":"Gitea account deactivation bypass via OAuth2 sign-in","severity":"high","exploited":false,"published_at":"2026-07-21T21:02:10+00:00","url":"https://junglewise.ai/threats/cve-2026-55987-gitea-account-deactivation-bypass-via-oauth2-sign-in"},{"cve":"CVE-2026-58435","cvss":5.4,"epss":0.0029,"slug":"cve-2026-58435-gitea-lfs-privilege-escalation-via-deploy-key-impersonation","title":"Gitea LFS privilege escalation via deploy key impersonation","severity":"medium","exploited":false,"published_at":"2026-07-21T21:00:51+00:00","url":"https://junglewise.ai/threats/cve-2026-58435-gitea-lfs-privilege-escalation-via-deploy-key-impersonation"},{"cve":"CVE-2026-55984","cvss":3.1,"epss":0.0046,"slug":"cve-2026-55984-gitea-null-pointer-dereference-in-addtime-api","title":"Gitea NULL pointer dereference in AddTime API","severity":"low","exploited":false,"published_at":"2026-07-21T20:59:14+00:00","url":"https://junglewise.ai/threats/cve-2026-55984-gitea-null-pointer-dereference-in-addtime-api"},{"cve":"CVE-2026-55982","cvss":4,"epss":0.0051,"slug":"cve-2026-55982-gitea-oidc-userinfo-scope-bypass-allows-identity-disclosure","title":"Gitea OIDC userinfo scope bypass allows identity disclosure","severity":"medium","exploited":false,"published_at":"2026-07-21T20:42:05+00:00","url":"https://junglewise.ai/threats/cve-2026-55982-gitea-oidc-userinfo-scope-bypass-allows-identity-disclosure"},{"cve":"CVE-2026-58434","cvss":4,"epss":0.0047,"slug":"cve-2026-58434-gitea-information-disclosure-via-starred-repository-metadata","title":"Gitea information disclosure via starred repository metadata after access revocation","severity":"medium","exploited":false,"published_at":"2026-07-21T20:41:49+00:00","url":"https://junglewise.ai/threats/cve-2026-58434-gitea-information-disclosure-via-starred-repository-metadata"},{"cve":"CVE-2026-54481","cvss":7.5,"epss":0.003,"slug":"cve-2026-54481-gitea-improper-certificate-validation-in-internal-api-client","title":"Gitea improper certificate validation in internal API client","severity":"high","exploited":false,"published_at":"2026-07-21T20:41:25+00:00","url":"https://junglewise.ai/threats/cve-2026-54481-gitea-improper-certificate-validation-in-internal-api-client"},{"cve":"CVE-2026-50105","cvss":4.3,"epss":0.0036,"slug":"cve-2026-50105-gitea-authorization-bypass-in-rss-and-atom-feed-handlers","title":"Gitea authorization bypass in RSS and Atom feed handlers","severity":"medium","exploited":false,"published_at":"2026-07-21T20:40:24+00:00","url":"https://junglewise.ai/threats/cve-2026-50105-gitea-authorization-bypass-in-rss-and-atom-feed-handlers"},{"cve":"CVE-2026-42931","cvss":6.5,"epss":0.0053,"slug":"cve-2026-42931-gitea-denial-of-service-via-unbounded-memory-allocation-in-npm","title":"Gitea denial of service via unbounded memory allocation in NPM API","severity":"medium","exploited":false,"published_at":"2026-07-21T20:39:37+00:00","url":"https://junglewise.ai/threats/cve-2026-42931-gitea-denial-of-service-via-unbounded-memory-allocation-in-npm"},{"cve":"CVE-2026-58445","cvss":3.1,"epss":0.0037,"slug":"cve-2026-58445-gitea-cross-repository-label-enumeration-oracle-in","title":"Gitea cross-repository label enumeration oracle in DeleteIssueLabel API","severity":"low","exploited":false,"published_at":"2026-07-21T20:39:22+00:00","url":"https://junglewise.ai/threats/cve-2026-58445-gitea-cross-repository-label-enumeration-oracle-in"},{"cve":"CVE-2026-58444","cvss":4.3,"epss":0.0036,"slug":"cve-2026-58444-gitea-token-scope-bypass-in-repository-home-page","title":"Gitea token scope bypass in repository home page","severity":"medium","exploited":false,"published_at":"2026-07-21T20:38:31+00:00","url":"https://junglewise.ai/threats/cve-2026-58444-gitea-token-scope-bypass-in-repository-home-page"},{"cve":"CVE-2026-58443","cvss":9.6,"epss":0.0058,"slug":"cve-2026-58443-gitea-public-only-token-scope-bypass-in-pull-request-updates","title":"Gitea public-only token scope bypass in pull request updates","severity":"critical","exploited":false,"published_at":"2026-07-21T20:38:06+00:00","url":"https://junglewise.ai/threats/cve-2026-58443-gitea-public-only-token-scope-bypass-in-pull-request-updates"},{"cve":"CVE-2026-58442","cvss":6.5,"epss":0.0043,"slug":"cve-2026-58442-gitea-ssrf-via-multi-answer-dns-allow-list-bypass-in-repository","title":"Gitea SSRF via multi-answer DNS allow-list bypass in repository migration","severity":"medium","exploited":false,"published_at":"2026-07-21T20:37:45+00:00","url":"https://junglewise.ai/threats/cve-2026-58442-gitea-ssrf-via-multi-answer-dns-allow-list-bypass-in-repository"},{"cve":"CVE-2026-58441","cvss":6.3,"epss":0.0017,"slug":"cve-2026-58441-gitea-ssrf-in-restore-repo-via-unsanitized-head-cloneurl","title":"Gitea SSRF in restore-repo via unsanitized Head.CloneURL","severity":"medium","exploited":false,"published_at":"2026-07-21T20:37:29+00:00","url":"https://junglewise.ai/threats/cve-2026-58441-gitea-ssrf-in-restore-repo-via-unsanitized-head-cloneurl"}],"weekly":[{"week":"2026-06-29","critical":9,"exploited":0,"vulnerabilities":40},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":2,"exploited":0,"vulnerabilities":39},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":1,"exploited":1,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"github.com/rclone/rclone (Go)","slug":"github-com-rclone-rclone","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/github-com-rclone-rclone"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/filebrowser/filebrowser/v2 (Go)","slug":"github-com-filebrowser-filebrowser-v2","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser-v2"},{"name":"github.com/fission/fission (Go)","slug":"github-com-fission-fission","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-fission-fission"},{"name":"github.com/klever-io/klever-go (Go)","slug":"github-com-klever-io-klever-go","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go"},{"name":"code.vikunja.io/api (Go)","slug":"code-vikunja-io-api","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api"},{"name":"github.com/cloudreve/Cloudreve/v4 (Go)","slug":"github-com-cloudreve-cloudreve-v4","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/github-com-cloudreve-cloudreve-v4"},{"name":"github.com/gotenberg/gotenberg/v8 (Go)","slug":"github-com-gotenberg-gotenberg-v8","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v8"},{"name":"github.com/nezhahq/nezha (Go)","slug":"github-com-nezhahq-nezha","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-nezhahq-nezha"},{"name":"github.com/fleetdm/fleet/v4 (Go)","slug":"github-com-fleetdm-fleet-v4","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/github-com-fleetdm-fleet-v4"},{"name":"github.com/juev/nebula-mesh (Go)","slug":"github-com-juev-nebula-mesh","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/github-com-juev-nebula-mesh"}],"technology":{"hub":true,"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://gitea.io/","repo_url":"https://github.com/go-gitea/gitea","description":"A self-hosted Git service written in Go, providing repository management and collaboration tools.","url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},"most_severe":[{"cve":"CVE-2026-60004","cvss":9.8,"epss":0.2399,"slug":"cve-2026-60004-gitea-code-injection-in-diffpatch-api","title":"Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.","severity":"critical","exploited":true,"published_at":"2026-08-26T20:17:56.01+00:00","url":"https://junglewise.ai/threats/cve-2026-60004-gitea-code-injection-in-diffpatch-api"},{"cve":"CVE-2026-20896","cvss":9.8,"epss":0.0276,"slug":"cve-2026-20896-gitea-docker-image-authentication-bypass-via-trusted-proxy","title":"Gitea Docker image authentication bypass via trusted proxy misconfiguration","severity":"critical","exploited":false,"published_at":"2026-07-03T21:16:56.66+00:00","url":"https://junglewise.ai/threats/cve-2026-20896-gitea-docker-image-authentication-bypass-via-trusted-proxy"},{"cve":"CVE-2026-26292","cvss":9.8,"epss":0.0065,"slug":"cve-2026-26292-gitea-migration-transport-bypass-in-lfs-mirror-operations","title":"Gitea migration transport bypass in LFS mirror operations","severity":"critical","exploited":false,"published_at":"2026-07-03T21:16:58.517+00:00","url":"https://junglewise.ai/threats/cve-2026-26292-gitea-migration-transport-bypass-in-lfs-mirror-operations"},{"cve":"CVE-2026-27780","cvss":9.8,"epss":0.0064,"slug":"cve-2026-27780-gitea-branch-protection-bypass-via-bufio-scanner-error-handling","title":"Gitea branch protection bypass via bufio.Scanner error handling in pre-receive hooks","severity":"critical","exploited":false,"published_at":"2026-07-03T21:16:59.347+00:00","url":"https://junglewise.ai/threats/cve-2026-27780-gitea-branch-protection-bypass-via-bufio-scanner-error-handling"},{"cve":"CVE-2026-58443","cvss":9.6,"epss":0.0058,"slug":"cve-2026-58443-gitea-public-only-token-scope-bypass-in-pull-request-updates","title":"Gitea public-only token scope bypass in pull request updates","severity":"critical","exploited":false,"published_at":"2026-07-21T20:38:06+00:00","url":"https://junglewise.ai/threats/cve-2026-58443-gitea-public-only-token-scope-bypass-in-pull-request-updates"},{"cve":"CVE-2026-22874","cvss":9.6,"epss":0.0046,"slug":"cve-2026-22874-gitea-ssrf-via-incomplete-hostmatcher-allow-list-filtering","title":"Gitea SSRF via incomplete hostmatcher allow-list filtering","severity":"critical","exploited":false,"published_at":"2026-07-03T21:16:57.157+00:00","url":"https://junglewise.ai/threats/cve-2026-22874-gitea-ssrf-via-incomplete-hostmatcher-allow-list-filtering"},{"cve":"CVE-2026-58426","cvss":9.6,"epss":0.003,"slug":"cve-2026-58426-gitea-actions-hmac-ambiguity-in-artifacts-v4-signed-urls","title":"Gitea Actions HMAC ambiguity in Artifacts V4 signed URLs","severity":"critical","exploited":false,"published_at":"2026-07-03T21:17:05.77+00:00","url":"https://junglewise.ai/threats/cve-2026-58426-gitea-actions-hmac-ambiguity-in-artifacts-v4-signed-urls"},{"cve":"CVE-2026-25718","cvss":9.1,"epss":0.0056,"slug":"cve-2026-25718-gitea-improper-link-resolution-in-template-repository-generation","title":"Gitea improper link resolution in template repository generation","severity":"critical","exploited":false,"published_at":"2026-07-03T21:16:57.823+00:00","url":"https://junglewise.ai/threats/cve-2026-25718-gitea-improper-link-resolution-in-template-repository-generation"},{"cve":"CVE-2026-22547","cvss":9.1,"epss":0.0052,"slug":"cve-2026-22547-gitea-improper-input-validation-in-repository-creation-fields","title":"Gitea improper input validation in repository creation fields","severity":"critical","exploited":false,"published_at":"2026-07-03T21:16:56.89+00:00","url":"https://junglewise.ai/threats/cve-2026-22547-gitea-improper-input-validation-in-repository-creation-fields"},{"cve":"CVE-2026-26247","cvss":9.1,"epss":0.005,"slug":"cve-2026-26247-gitea-oauth2-pkce-s256-verifier-bypass","title":"Gitea OAuth2 PKCE S256 verifier bypass","severity":"critical","exploited":false,"published_at":"2026-07-03T21:16:58.417+00:00","url":"https://junglewise.ai/threats/cve-2026-26247-gitea-oauth2-pkce-s256-verifier-bypass"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}