Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Gitea

11 known vulnerabilities

4
CRITICAL
1
HIGH
5
MEDIUM
1
LOW

Top Products

gitea 11
11 CVEs
9.8
CVE-2026-60004 KEV

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

9.1
CVE-2026-20912

Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a

6.5
CVE-2026-20904

Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to cha

9.1
CVE-2026-20897

Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repos

4.3
CVE-2026-20888

Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with rea

6.5
CVE-2026-20883

Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository

6.5
CVE-2026-20800

Gitea's notification API does not re-validate repository access permissions when returning notification details. After a

9.1
CVE-2026-20750

Gitea does not properly validate project ownership in organization project operations. A user with project write access

7.5
CVE-2026-20736

Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachmen

3.5
CVE-2026-0798

Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repos

5.3
CVE-2025-69413

In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username e

Frequently Asked Questions

How many CVEs affect Gitea?

Gitea has 11 CVE records in our database, including 4 critical and 1 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Gitea vulnerabilities?

Gitea has 4 critical severity (CVSS 9.0+) and 1 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Gitea vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Gitea products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Gitea Vulnerabilities

CyberStrike scans your infrastructure for Gitea vulnerabilities and provides real-time remediation guidance.

Get Started