{"schema_version":1,"title":"gitea.dev (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 44 vulnerabilities in gitea.dev (Go): 0 in the last 7 days and 44 in the last 90 days, 3 of them critical and 1 exploited in the wild. The most recent, CVE-2026-60004, was published on 26 August 2026.","url":"https://junglewise.ai/threats/technologies/gitea-dev","json_url":"https://junglewise.ai/threats/technologies/gitea-dev.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/gitea-dev","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":9,"all_time":44,"critical":3,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":44,"last_365_days":44},"latest":[{"cve":"CVE-2026-60004","cvss":9.8,"epss":0.2399,"slug":"cve-2026-60004-gitea-code-injection-in-diffpatch-api","title":"Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.","severity":"critical","exploited":true,"published_at":"2026-08-26T20:17:56.01+00:00","url":"https://junglewise.ai/threats/cve-2026-60004-gitea-code-injection-in-diffpatch-api"},{"cve":"CVE-2026-34966","cvss":3.1,"epss":0.0039,"slug":"cve-2026-34966-gitea-ssrf-via-migration-asset-downloads-bypasses-hostmatcher","title":"GO-2026-6039 - Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher , Reads Internal Files and Cloud Metadata in gitea.dev","severity":"low","exploited":false,"published_at":"2026-07-22T20:36:35+00:00","url":"https://junglewise.ai/threats/cve-2026-34966-gitea-ssrf-via-migration-asset-downloads-bypasses-hostmatcher"},{"cve":"CVE-2026-58429","cvss":4.9,"epss":0.0047,"slug":"cve-2026-58429-gitea-public-only-token-scope-bypass-in-organization-and","title":"Gitea public-only token scope bypass in Organization and Permission endpoints","severity":"medium","exploited":false,"published_at":"2026-07-21T21:56:04+00:00","url":"https://junglewise.ai/threats/cve-2026-58429-gitea-public-only-token-scope-bypass-in-organization-and"},{"cve":"CVE-2026-58511","cvss":3.1,"epss":0.0039,"slug":"cve-2026-58511-gitea-plaintext-webhook-authorization-header-exposure-in-api","title":"Gitea plaintext webhook authorization header exposure in API","severity":"low","exploited":false,"published_at":"2026-07-21T21:52:49+00:00","url":"https://junglewise.ai/threats/cve-2026-58511-gitea-plaintext-webhook-authorization-header-exposure-in-api"},{"cve":"CVE-2026-57897","cvss":6.5,"epss":0.0041,"slug":"cve-2026-57897-gitea-information-disclosure-in-organization-actions-api","title":"Gitea information disclosure in organization Actions API","severity":"medium","exploited":false,"published_at":"2026-07-21T21:52:02+00:00","url":"https://junglewise.ai/threats/cve-2026-57897-gitea-information-disclosure-in-organization-actions-api"},{"cve":"CVE-2026-58510","cvss":4.3,"epss":0.0033,"slug":"cve-2026-58510-gitea-information-disclosure-via-stale-watches-in-rest-api","title":"Gitea information disclosure via stale watches in REST API","severity":"medium","exploited":false,"published_at":"2026-07-21T21:51:41+00:00","url":"https://junglewise.ai/threats/cve-2026-58510-gitea-information-disclosure-via-stale-watches-in-rest-api"},{"cve":"CVE-2026-58431","cvss":4.3,"epss":0.0033,"slug":"cve-2026-58431-gitea-incorrect-authorization-for-public-only-tokens-in-team-api","title":"Gitea incorrect authorization for public-only tokens in team API routes","severity":"medium","exploited":false,"published_at":"2026-07-21T21:50:11+00:00","url":"https://junglewise.ai/threats/cve-2026-58431-gitea-incorrect-authorization-for-public-only-tokens-in-team-api"},{"cve":"CVE-2026-58427","cvss":5.3,"epss":0.0047,"slug":"cve-2026-58427-gitea-information-disclosure-in-private-organization-member-list","title":"Gitea information disclosure in private organization member list","severity":"medium","exploited":false,"published_at":"2026-07-21T21:49:00+00:00","url":"https://junglewise.ai/threats/cve-2026-58427-gitea-information-disclosure-in-private-organization-member-list"},{"cve":"CVE-2026-58314","cvss":7.7,"epss":0.004,"slug":"cve-2026-58314-gitea-ssrf-in-webhooks-and-openid-discovery","title":"Gitea SSRF in webhooks and OpenID discovery","severity":"high","exploited":false,"published_at":"2026-07-21T21:16:00+00:00","url":"https://junglewise.ai/threats/cve-2026-58314-gitea-ssrf-in-webhooks-and-openid-discovery"},{"cve":"CVE-2026-58436","cvss":4,"epss":0.0061,"slug":"cve-2026-58436-gitea-quadratic-time-dos-in-locale-middleware-via-accept-language","title":"Gitea quadratic-time DoS in Locale middleware via Accept-Language header","severity":"high","exploited":false,"published_at":"2026-07-21T21:15:47+00:00","url":"https://junglewise.ai/threats/cve-2026-58436-gitea-quadratic-time-dos-in-locale-middleware-via-accept-language"},{"cve":"CVE-2026-56657","cvss":3.1,"epss":0.0017,"slug":"cve-2026-56657-gitea-ssh-key-parser-denial-of-service-in-normalization-loop","title":"Gitea SSH key parser denial of service in normalization loop","severity":"medium","exploited":false,"published_at":"2026-07-21T21:09:57+00:00","url":"https://junglewise.ai/threats/cve-2026-56657-gitea-ssh-key-parser-denial-of-service-in-normalization-loop"},{"cve":"CVE-2026-58437","cvss":7.1,"epss":0.0034,"slug":"cve-2026-58437-gitea-repository-visibility-manipulation-via-git-push-options","title":"Gitea repository visibility manipulation via Git push options","severity":"high","exploited":false,"published_at":"2026-07-21T21:02:44+00:00","url":"https://junglewise.ai/threats/cve-2026-58437-gitea-repository-visibility-manipulation-via-git-push-options"},{"cve":"CVE-2026-55987","cvss":8.1,"epss":0.0041,"slug":"cve-2026-55987-gitea-account-deactivation-bypass-via-oauth2-sign-in","title":"Gitea account deactivation bypass via OAuth2 sign-in","severity":"high","exploited":false,"published_at":"2026-07-21T21:02:10+00:00","url":"https://junglewise.ai/threats/cve-2026-55987-gitea-account-deactivation-bypass-via-oauth2-sign-in"},{"cve":"CVE-2026-58435","cvss":5.4,"epss":0.0029,"slug":"cve-2026-58435-gitea-lfs-privilege-escalation-via-deploy-key-impersonation","title":"Gitea LFS privilege escalation via deploy key impersonation","severity":"medium","exploited":false,"published_at":"2026-07-21T21:00:51+00:00","url":"https://junglewise.ai/threats/cve-2026-58435-gitea-lfs-privilege-escalation-via-deploy-key-impersonation"},{"cve":"CVE-2026-58420","cvss":4,"epss":0.0047,"slug":"cve-2026-58420-gitea-local-file-inclusion-in-migration-restore","title":"Gitea Local File Inclusion in Migration Restore","severity":"medium","exploited":false,"published_at":"2026-07-21T20:59:53+00:00","url":"https://junglewise.ai/threats/cve-2026-58420-gitea-local-file-inclusion-in-migration-restore"},{"cve":"CVE-2026-55984","cvss":3.1,"epss":0.0046,"slug":"cve-2026-55984-gitea-null-pointer-dereference-in-addtime-api","title":"Gitea NULL pointer dereference in AddTime API","severity":"low","exploited":false,"published_at":"2026-07-21T20:59:14+00:00","url":"https://junglewise.ai/threats/cve-2026-55984-gitea-null-pointer-dereference-in-addtime-api"},{"cve":"CVE-2026-55982","cvss":4,"epss":0.0051,"slug":"cve-2026-55982-gitea-oidc-userinfo-scope-bypass-allows-identity-disclosure","title":"Gitea OIDC userinfo scope bypass allows identity disclosure","severity":"medium","exploited":false,"published_at":"2026-07-21T20:42:05+00:00","url":"https://junglewise.ai/threats/cve-2026-55982-gitea-oidc-userinfo-scope-bypass-allows-identity-disclosure"},{"cve":"CVE-2026-58434","cvss":4,"epss":0.0047,"slug":"cve-2026-58434-gitea-information-disclosure-via-starred-repository-metadata","title":"Gitea information disclosure via starred repository metadata after access revocation","severity":"medium","exploited":false,"published_at":"2026-07-21T20:41:49+00:00","url":"https://junglewise.ai/threats/cve-2026-58434-gitea-information-disclosure-via-starred-repository-metadata"},{"cve":"CVE-2026-54481","cvss":7.5,"epss":0.003,"slug":"cve-2026-54481-gitea-improper-certificate-validation-in-internal-api-client","title":"Gitea improper certificate validation in internal API client","severity":"high","exploited":false,"published_at":"2026-07-21T20:41:25+00:00","url":"https://junglewise.ai/threats/cve-2026-54481-gitea-improper-certificate-validation-in-internal-api-client"},{"cve":"CVE-2026-58417","cvss":4,"epss":0.0047,"slug":"cve-2026-58417-gitea-information-disclosure-in-private-organization-membership","title":"Gitea information disclosure in private organization membership API","severity":"medium","exploited":false,"published_at":"2026-07-21T20:40:55+00:00","url":"https://junglewise.ai/threats/cve-2026-58417-gitea-information-disclosure-in-private-organization-membership"},{"cve":"CVE-2026-50105","cvss":4.3,"epss":0.0036,"slug":"cve-2026-50105-gitea-authorization-bypass-in-rss-and-atom-feed-handlers","title":"Gitea authorization bypass in RSS and Atom feed handlers","severity":"medium","exploited":false,"published_at":"2026-07-21T20:40:24+00:00","url":"https://junglewise.ai/threats/cve-2026-50105-gitea-authorization-bypass-in-rss-and-atom-feed-handlers"},{"cve":"CVE-2026-58416","cvss":6.3,"epss":0.0031,"slug":"cve-2026-58416-gitea-authorization-bypass-in-actions-collaborative-owner-access","title":"Gitea authorization bypass in Actions collaborative-owner access","severity":"medium","exploited":false,"published_at":"2026-07-21T20:40:03+00:00","url":"https://junglewise.ai/threats/cve-2026-58416-gitea-authorization-bypass-in-actions-collaborative-owner-access"},{"cve":"CVE-2026-42931","cvss":6.5,"epss":0.0053,"slug":"cve-2026-42931-gitea-denial-of-service-via-unbounded-memory-allocation-in-npm","title":"Gitea denial of service via unbounded memory allocation in NPM API","severity":"medium","exploited":false,"published_at":"2026-07-21T20:39:37+00:00","url":"https://junglewise.ai/threats/cve-2026-42931-gitea-denial-of-service-via-unbounded-memory-allocation-in-npm"},{"cve":"CVE-2026-58445","cvss":3.1,"epss":0.0037,"slug":"cve-2026-58445-gitea-cross-repository-label-enumeration-oracle-in","title":"Gitea cross-repository label enumeration oracle in DeleteIssueLabel API","severity":"low","exploited":false,"published_at":"2026-07-21T20:39:22+00:00","url":"https://junglewise.ai/threats/cve-2026-58445-gitea-cross-repository-label-enumeration-oracle-in"},{"cve":"CVE-2026-58444","cvss":4.3,"epss":0.0036,"slug":"cve-2026-58444-gitea-token-scope-bypass-in-repository-home-page","title":"Gitea token scope bypass in repository home page","severity":"medium","exploited":false,"published_at":"2026-07-21T20:38:31+00:00","url":"https://junglewise.ai/threats/cve-2026-58444-gitea-token-scope-bypass-in-repository-home-page"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":2,"exploited":0,"vulnerabilities":42},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":1,"exploited":1,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"github.com/rclone/rclone (Go)","slug":"github-com-rclone-rclone","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/github-com-rclone-rclone"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/filebrowser/filebrowser/v2 (Go)","slug":"github-com-filebrowser-filebrowser-v2","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser-v2"},{"name":"github.com/fission/fission (Go)","slug":"github-com-fission-fission","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-fission-fission"},{"name":"github.com/klever-io/klever-go (Go)","slug":"github-com-klever-io-klever-go","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go"},{"name":"code.vikunja.io/api (Go)","slug":"code-vikunja-io-api","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api"},{"name":"github.com/cloudreve/Cloudreve/v4 (Go)","slug":"github-com-cloudreve-cloudreve-v4","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/github-com-cloudreve-cloudreve-v4"},{"name":"github.com/gotenberg/gotenberg/v8 (Go)","slug":"github-com-gotenberg-gotenberg-v8","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v8"},{"name":"github.com/nezhahq/nezha (Go)","slug":"github-com-nezhahq-nezha","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-nezhahq-nezha"},{"name":"github.com/fleetdm/fleet/v4 (Go)","slug":"github-com-fleetdm-fleet-v4","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/github-com-fleetdm-fleet-v4"}],"technology":{"hub":true,"name":"gitea.dev (Go)","slug":"gitea-dev","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://gitea.com/","repo_url":"https://github.com/go-gitea/gitea","description":"A self-hosted Git service written in Go.","url":"https://junglewise.ai/threats/technologies/gitea-dev"},"most_severe":[{"cve":"CVE-2026-60004","cvss":9.8,"epss":0.2399,"slug":"cve-2026-60004-gitea-code-injection-in-diffpatch-api","title":"Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.","severity":"critical","exploited":true,"published_at":"2026-08-26T20:17:56.01+00:00","url":"https://junglewise.ai/threats/cve-2026-60004-gitea-code-injection-in-diffpatch-api"},{"cve":"CVE-2026-58443","cvss":9.6,"epss":0.0058,"slug":"cve-2026-58443-gitea-public-only-token-scope-bypass-in-pull-request-updates","title":"Gitea public-only token scope bypass in pull request updates","severity":"critical","exploited":false,"published_at":"2026-07-21T20:38:06+00:00","url":"https://junglewise.ai/threats/cve-2026-58443-gitea-public-only-token-scope-bypass-in-pull-request-updates"},{"cve":"CVE-2026-56750","cvss":4,"epss":0.0048,"slug":"cve-2026-56750-gitea-insufficient-session-expiration-in-remember-me-auth-token","title":"Gitea insufficient session expiration in Remember-Me auth token","severity":"critical","exploited":false,"published_at":"2026-07-21T20:20:21+00:00","url":"https://junglewise.ai/threats/cve-2026-56750-gitea-insufficient-session-expiration-in-remember-me-auth-token"},{"cve":"CVE-2026-57894","cvss":8.5,"epss":0.0036,"slug":"cve-2026-57894-gitea-ssrf-and-repository-exfiltration-via-git-http-redirects","title":"Gitea SSRF and repository exfiltration via Git HTTP redirects","severity":"high","exploited":false,"published_at":"2026-07-21T19:17:21+00:00","url":"https://junglewise.ai/threats/cve-2026-57894-gitea-ssrf-and-repository-exfiltration-via-git-http-redirects"},{"cve":"CVE-2026-55987","cvss":8.1,"epss":0.0041,"slug":"cve-2026-55987-gitea-account-deactivation-bypass-via-oauth2-sign-in","title":"Gitea account deactivation bypass via OAuth2 sign-in","severity":"high","exploited":false,"published_at":"2026-07-21T21:02:10+00:00","url":"https://junglewise.ai/threats/cve-2026-55987-gitea-account-deactivation-bypass-via-oauth2-sign-in"},{"cve":"CVE-2026-58314","cvss":7.7,"epss":0.004,"slug":"cve-2026-58314-gitea-ssrf-in-webhooks-and-openid-discovery","title":"Gitea SSRF in webhooks and OpenID discovery","severity":"high","exploited":false,"published_at":"2026-07-21T21:16:00+00:00","url":"https://junglewise.ai/threats/cve-2026-58314-gitea-ssrf-in-webhooks-and-openid-discovery"},{"cve":"CVE-2026-54481","cvss":7.5,"epss":0.003,"slug":"cve-2026-54481-gitea-improper-certificate-validation-in-internal-api-client","title":"Gitea improper certificate validation in internal API client","severity":"high","exploited":false,"published_at":"2026-07-21T20:41:25+00:00","url":"https://junglewise.ai/threats/cve-2026-54481-gitea-improper-certificate-validation-in-internal-api-client"},{"cve":"CVE-2026-58437","cvss":7.1,"epss":0.0034,"slug":"cve-2026-58437-gitea-repository-visibility-manipulation-via-git-push-options","title":"Gitea repository visibility manipulation via Git push options","severity":"high","exploited":false,"published_at":"2026-07-21T21:02:44+00:00","url":"https://junglewise.ai/threats/cve-2026-58437-gitea-repository-visibility-manipulation-via-git-push-options"},{"cve":"CVE-2026-28740","cvss":7.1,"epss":0.0032,"slug":"cve-2026-28740-gitea-authorization-bypass-in-git-lfs-object-reuse","title":"Gitea authorization bypass in Git LFS object reuse","severity":"high","exploited":false,"published_at":"2026-07-03T21:16:59.89+00:00","url":"https://junglewise.ai/threats/cve-2026-28740-gitea-authorization-bypass-in-git-lfs-object-reuse"},{"cve":"CVE-2026-58436","cvss":4,"epss":0.0061,"slug":"cve-2026-58436-gitea-quadratic-time-dos-in-locale-middleware-via-accept-language","title":"Gitea quadratic-time DoS in Locale middleware via Accept-Language header","severity":"high","exploited":false,"published_at":"2026-07-21T21:15:47+00:00","url":"https://junglewise.ai/threats/cve-2026-58436-gitea-quadratic-time-dos-in-locale-middleware-via-accept-language"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}