Technology · Go
github.com/go-gitea/gitea (Go) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 20 vulnerabilities in github.com/go-gitea/gitea (Go): 0 in the last 7 days and 1 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-25779, was published on 3 July 2026.
- Last 7 days
- 0
- Last 90 days
- 1
- Critical, all time
- 3
- Exploited in the wild
- 0
About github.com/go-gitea/gitea (Go)
Gitea is an open-source forge software package for hosting software development version control using Git.
Latest github.com/go-gitea/gitea (Go) vulnerabilities
- CVE-2026-25779: Gitea open redirect via backslash-encoded paths in redirect_to parametermediumCVSS 4EPSS 0.3%
- CVE-2026-20800: GO-2026-4362 - Gitea improperly exposes issue and pull request titles in code.gitea.io/giteamediumCVSS 4EPSS 0.4%
- CVE-2026-20904: GO-2026-4369 - Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/giteamediumCVSS 4EPSS 0.3%
- CVE-2026-20888: GO-2026-4366 - Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in…mediumCVSS 4EPSS 0.3%
- CVE-2026-20883: GO-2026-4368 - Gitea improperly exposes issue titles and repository names through previously started stopwatches in…mediumCVSS 4EPSS 0.4%
- CVE-2026-20912: Gitea improper ownership validation in release attachmentscriticalCVSS 9.1EPSS 0.5%
- CVE-2026-20897: Gitea authorization bypass in Git LFS lock deletioncriticalCVSS 9.1EPSS 0.5%
- CVE-2026-20750: Gitea improper access control in organization project operationscriticalCVSS 9.1EPSS 0.4%
- CVE-2022-42968: GO-2022-1065 - Gitea vulnerable to Argument Injection in code.gitea.io/gitealowCVSS 3.1EPSS 1.2%
- CVE-2019-11228: GO-2022-0862 - Gitea Improper Input Validation in github.com/go-gitea/gitealowCVSS 3EPSS 1.4%
- CVE-2019-11229: GO-2022-0846 - Gitea Remote Code Execution in github.com/go-gitea/gitealowCVSS 3.1EPSS 55.0%
- CVE-2020-13246: GO-2022-0830 - Denial of Service in Gitea in code.gitea.io/gitealowCVSS 3.1EPSS 2.0%
- CVE-2018-1000803: GO-2022-0823 - Gitea Exposes Private Email Addresses in github.com/go-gitea/gitealowCVSS 3.1EPSS 1.3%
- CVE-2021-45328: GO-2022-0579 - Open redirect in Gitea in github.com/go-gitea/gitealowCVSS 3.1EPSS 0.9%
- CVE-2021-45329: GO-2022-0314 - Cross-site Scripting in Gitea in github.com/go-gitea/gitealowCVSS 3.1EPSS 0.8%
- CVE-2021-45326: GO-2022-0309 - Cross Site Request Forgery in Gitea in github.com/go-gitea/gitealowCVSS 3.1EPSS 0.6%
- CVE-2021-45327: GO-2022-0310 - Capture-replay in Gitea in code.gitea.io/gitealowCVSS 3.1EPSS 2.1%
- CVE-2021-45325: GO-2022-0308 - Gitea displaying raw OpenID error in UI in github.com/go-gitea/gitealowCVSS 3.1EPSS 1.1%
- CVE-2021-3382: GO-2024-2757 - Buffer Overflow in gitea in code.gitea.io/gitealowCVSS 3.1EPSS 1.8%
- CVE-2020-28991: Improper Access Control in GitealowCVSS 3.1EPSS 1.7%
Most severe github.com/go-gitea/gitea (Go) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-20912: Gitea improper ownership validation in release attachmentscriticalCVSS 9.1EPSS 0.5%
- CVE-2026-20897: Gitea authorization bypass in Git LFS lock deletioncriticalCVSS 9.1EPSS 0.5%
- CVE-2026-20750: Gitea improper access control in organization project operationscriticalCVSS 9.1EPSS 0.4%
- CVE-2026-20800: GO-2026-4362 - Gitea improperly exposes issue and pull request titles in code.gitea.io/giteamediumCVSS 4EPSS 0.4%
- CVE-2026-20883: GO-2026-4368 - Gitea improperly exposes issue titles and repository names through previously started stopwatches in…mediumCVSS 4EPSS 0.4%
- CVE-2026-25779: Gitea open redirect via backslash-encoded paths in redirect_to parametermediumCVSS 4EPSS 0.3%
- CVE-2026-20888: GO-2026-4366 - Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in…mediumCVSS 4EPSS 0.3%
- CVE-2026-20904: GO-2026-4369 - Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/giteamediumCVSS 4EPSS 0.3%
- CVE-2019-11229: GO-2022-0846 - Gitea Remote Code Execution in github.com/go-gitea/gitealowCVSS 3.1EPSS 55.0%
- CVE-2021-45327: GO-2022-0310 - Capture-replay in Gitea in code.gitea.io/gitealowCVSS 3.1EPSS 2.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/github-com-go-gitea-gitea.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "github.com/go-gitea/gitea (Go) vulnerabilities", https://junglewise.ai/threats/technologies/github-com-go-gitea-gitea, 28 September 2026.