Technology · Gitea
Gitea vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 89 vulnerabilities in Gitea: 0 in the last 7 days and 84 in the last 90 days, 14 of them critical and 1 exploited in the wild. The most recent, CVE-2026-60004, was published on 26 August 2026.
- Last 7 days
- 0
- Last 90 days
- 84
- Critical, all time
- 14
- Exploited in the wild
- 1
About Gitea
Lightweight self-hosted Git service written in Go.
Latest Gitea vulnerabilities
- CVE-2026-60004: Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.criticalexploited in the wildCVSS 9.8EPSS 24.0%
- CVE-2026-58429: Gitea public-only token scope bypass in Organization and Permission endpointsmediumCVSS 4.9
- CVE-2026-59765: Gitea SSRF and local file read via migration asset bypassmediumCVSS 6.9
- CVE-2026-58511: Gitea plaintext webhook authorization header exposure in APIlowCVSS 2.7
- CVE-2026-57897: Gitea information disclosure in organization Actions APImediumCVSS 6.5
- CVE-2026-58510: Gitea information disclosure via stale watches in REST APImediumCVSS 4.3
- CVE-2026-58431: Gitea incorrect authorization for public-only tokens in team API routesmediumCVSS 4.3
- CVE-2026-58427: Gitea information disclosure in private organization member listmediumCVSS 5.3
- CVE-2026-58314: Gitea SSRF in webhooks and OpenID discoveryhighCVSS 7.7
- CVE-2026-58436: Gitea quadratic-time DoS in Locale middleware via Accept-Language headerhighCVSS 7.5
- CVE-2026-56657: Gitea SSH key parser denial of service in normalization loopmediumCVSS 6.5
- CVE-2026-58437: Gitea repository visibility manipulation via Git push optionshighCVSS 7.1
- CVE-2026-55987: Gitea account deactivation bypass via OAuth2 sign-inhighCVSS 8.1
- CVE-2026-58435: Gitea LFS privilege escalation via deploy key impersonationmediumCVSS 5.4
- CVE-2026-58420: Gitea Local File Inclusion in Migration RestoremediumCVSS 6.7
- CVE-2026-55984: Gitea NULL pointer dereference in AddTime APIlowCVSS 2.7
- CVE-2026-55982: Gitea OIDC userinfo scope bypass allows identity disclosuremediumCVSS 5.3
- CVE-2026-58434: Gitea information disclosure via starred repository metadata after access revocationlowCVSS 2.3
- CVE-2026-54481: Gitea improper certificate validation in internal API clienthighCVSS 7.5
- CVE-2026-58417: Gitea information disclosure in private organization membership APImediumCVSS 5.3
- CVE-2026-50105: Gitea authorization bypass in RSS and Atom feed handlersmediumCVSS 4.3
- CVE-2026-58416: Gitea authorization bypass in Actions collaborative-owner accessmediumCVSS 6.3
- CVE-2026-42931: Gitea denial of service via unbounded memory allocation in NPM APImediumCVSS 6.5
- CVE-2026-58445: Gitea cross-repository label enumeration oracle in DeleteIssueLabel APIlowCVSS 2.7
- CVE-2026-58444: Gitea token scope bypass in repository home pagemediumCVSS 4.3
Most severe Gitea vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-60004: Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.criticalexploited in the wildCVSS 9.8EPSS 24.0%
- CVE-2026-26292: Gitea migration transport bypass in LFS mirror operationscriticalCVSS 9.8EPSS 0.7%
- CVE-2026-27780: Gitea branch protection bypass via bufio.Scanner error handling in pre-receive hookscriticalCVSS 9.8EPSS 0.6%
- CVE-2026-22874: Gitea SSRF via incomplete hostmatcher allow-list filteringcriticalCVSS 9.6EPSS 0.5%
- CVE-2026-58426: Gitea Actions HMAC ambiguity in Artifacts V4 signed URLscriticalCVSS 9.6EPSS 0.2%
- CVE-2026-58443: Gitea public-only token scope bypass in pull request updatescriticalCVSS 9.6
- CVE-2026-25718: Gitea improper link resolution in template repository generationcriticalCVSS 9.1EPSS 0.6%
- CVE-2026-22547: Gitea improper input validation in repository creation fieldscriticalCVSS 9.1EPSS 0.5%
- CVE-2026-26247: Gitea OAuth2 PKCE S256 verifier bypasscriticalCVSS 9.1EPSS 0.5%
- CVE-2026-26232: Gitea OAuth2 authorization code reuse and expiry vulnerabilitycriticalCVSS 9.1EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 39 | 8 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 44 | 2 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 1 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/gitea.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Gitea vulnerabilities", https://junglewise.ai/threats/technologies/gitea, 26 September 2026.