Known Vulnerabilities for products from Gitea
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Gitea".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-20912 json | Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a priva... | Not Provided | 2026-01-22 | 2026-06-27 |
| CVE-2026-20897 json | Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository... | Not Provided | 2026-01-22 | 2026-06-27 |
| CVE-2026-20750 json | Gitea does not properly validate project ownership in organization project operations. A user with project write access in on... | Not Provided | 2026-01-22 | 2026-06-27 |
| CVE-2023-3515 json | Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4. | 4.4 - MEDIUM | 2023-07-05 | 2023-07-11 |
| CVE-2022-46685 json | In Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did not support credentials mas... | 4.3 - MEDIUM | 2022-12-12 | 2022-12-12 |
| CVE-2022-42968 json | Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. | 9.8 - CRITICAL | 2022-10-16 | 2022-12-03 |
| CVE-2022-38795 json | In Gitea through 1.17.1, repo cloning can occur in the migration function. | 6.5 - MEDIUM | 2023-08-07 | 2023-08-09 |
| CVE-2022-38183 json | In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an att... | 6.5 - MEDIUM | 2022-08-12 | 2023-08-08 |
| CVE-2022-30781 json | Gitea before 1.16.7 does not escape git fetch remote. | 7.5 - HIGH | 2022-05-16 | 2023-01-27 |
| CVE-2022-27313 json | An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting th... | 7.5 - HIGH | 2022-05-03 | 2022-05-11 |
| CVE-2022-1928 json | Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9. | 5.4 - MEDIUM | 2022-05-29 | 2022-11-16 |
| CVE-2022-1058 json | Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5. | 6.1 - MEDIUM | 2022-03-24 | 2022-03-29 |
| CVE-2022-0905 json | Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4. | 7.1 - HIGH | 2022-03-10 | 2023-06-29 |
| CVE-2021-45331 json | An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If cap... | 9.8 - CRITICAL | 2022-02-09 | 2022-02-14 |
| CVE-2021-45330 json | An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not bein... | 9.8 - CRITICAL | 2022-02-09 | 2022-07-12 |
| CVE-2021-45329 json | Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/is... | 6.1 - MEDIUM | 2022-02-08 | 2022-02-11 |
| CVE-2021-45328 json | Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs. | 6.1 - MEDIUM | 2022-02-08 | 2022-02-11 |
| CVE-2021-45327 json | Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin ... | 9.8 - CRITICAL | 2022-02-08 | 2023-08-08 |
| CVE-2021-45326 json | Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially ... | 8.8 - HIGH | 2022-02-08 | 2022-02-11 |
| CVE-2021-45325 json | Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL. | 7.5 - HIGH | 2022-02-08 | 2022-02-11 |
Known software with vulnerabilities from Gitea
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Gitea | Gitea | 0.9.99 |