PatchSiren

Gitea CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Gitea CVE published 2026-08-05

CVE-2026-34966

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T21:16:58.187Z and has not been modified since then. Gitea versions prior to 1.27.0 contain a server-side request forgery (SSRF) vulnerability that allows authenticated attackers to bypass SSRF protections. The vulnerability is exploited through HTTP fetch operations in migration and OAuth avatar [truncated]

HIGH Gitea CVE published 2026-07-03

CVE-2026-28740

CVE-2026-28740 is a high-severity vulnerability in Gitea, a self-hosted Git service. The issue allows Git LFS object reuse to authorize private source objects for users with repository access but lacking Code-unit access. This vulnerability was published on 2026-07-03T21:16:59.890Z and last modified on 2026-07-07T18:16:38.327Z. The vulnerability has significant implications for Gitea users, particularly t [truncated]

HIGH Gitea CVE published 2026-07-03

CVE-2026-28737

CVE-2026-28737 is a high-severity vulnerability in Gitea, a self-hosted Git service. It allows stored cross-site scripting (XSS) attacks through the extensionsRequired field in glTF files rendered by the 3D file viewer. The vulnerability affects Gitea versions from 1.25.0 before 1.26.0. Successful exploitation could allow attackers to inject malicious scripts into the 3D file viewer, potentially leading t [truncated]

MEDIUM Gitea CVE published 2026-07-03

CVE-2026-28705

CVE-2026-28705 is a MEDIUM severity vulnerability in Gitea versions before 1.25.5. The vulnerability occurs when Gitea uses release tag names and asset names as filesystem path components during the dumping of release assets. This allows specially crafted names to affect the dump output paths. The vulnerability has a CVSS score of 5.3 and is classified under CWE-22. Users of Gitea versions before 1.25.5 s [truncated]

HIGH Gitea CVE published 2026-07-03

CVE-2026-27771

CVE-2026-27771 is a high-severity vulnerability in Gitea versions up to and including 1.26.1. The vulnerability is caused by insufficient permission checks for Composer package source links, which can expose private or internal package source information. The CVE record was published on 2026-07-03T21:16:59.043Z and has not been modified since then. The NVD entry is currently Deferred. Users of Gitea versi [truncated]

MEDIUM Gitea CVE published 2026-07-03

CVE-2026-27761

CVE-2026-27761 is a medium-severity vulnerability in Gitea versions up to and including 1.26.2. The vulnerability allows repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope. This issue affects users of Gitea and requires immediate attention to mitigate potential exposure.

HIGH Gitea CVE published 2026-07-03

CVE-2026-27660

CVE-2026-27660 is a high-severity vulnerability in Gitea versions before 1.25.5. The issue allows draft release data or attachments to be accessed without the required write permission. This vulnerability has a CVSS score of 7.5 and is considered HIGH severity. The vulnerability exists in Gitea versions before 1.25.5, where draft release data or attachments can be accessed without the required write permi [truncated]

HIGH Gitea CVE published 2026-07-03

CVE-2026-27657

CVE-2026-27657 is a high-severity vulnerability in Gitea, a self-hosted Git service. Versions prior to 1.25.5 are affected. An attacker can change another user's primary email address, potentially leading to phishing or account takeover attempts. This vulnerability has a CVSS score of 7.5, indicating a high severity level. Gitea administrators should be aware of this vulnerability and take necessary actio [truncated]

HIGH Gitea CVE published 2026-07-03

CVE-2026-26307

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-03T21:16:58.620Z and has not been modified since then. Gitea versions before 1.25.5 are affected by a resource exhaustion vulnerability due to lack of timeout enforcement on git grep searches. This vulnerability can be exploited by attackers to consume server resources, potentially leading to denial [truncated]

CRITICAL Gitea CVE published 2026-07-03

CVE-2026-26292

CVE-2026-26292 is a critical vulnerability in Gitea versions before 1.25.5. The issue arises from Gitea not using the migration HTTP transport for LFS push and sync mirror operations, effectively bypassing the configured migration transport protections for those LFS requests. This vulnerability has a CVSS score of 9.8 and is considered CRITICAL. The vulnerability can be exploited remotely without authenti [truncated]

CRITICAL Gitea CVE published 2026-07-03

CVE-2026-26247

Gitea versions before 1.25.5 have a critical vulnerability (CVE-2026-26247) that allows token exchange without the expected verifier check due to incorrect persistence of the OAuth2 PKCE S256 challenge method. This issue affects Gitea instances prior to version 1.25.5. The vulnerability has a CVSS score of 9.1 and is considered critical. Administrators and users of Gitea instances should apply the patch t [truncated]

CRITICAL Gitea CVE published 2026-07-03

CVE-2026-26232

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-03T21:16:58.313Z and has not been modified since then. Gitea versions before 1.25.5 have a critical vulnerability related to OAuth2 authorization code expiry and single-use behavior during token exchange. This could potentially allow attackers to bypass authorization mechanisms. Administrators and u [truncated]

HIGH Gitea CVE published 2026-07-03

CVE-2026-26231

CVE-2026-26231 is a high-severity vulnerability in Gitea versions up to 1.26.1. The Allow edits from maintainers permission path incorrectly authorizes commits to repositories that users can read but should not write to. This issue has a CVSS score of 8.5 and is considered HIGH severity. The vulnerability exists due to a flaw in the permission system of Gitea, specifically in how the 'Allow edits from mai [truncated]

MEDIUM Gitea CVE published 2026-07-03

CVE-2026-25782

CVE-2026-25782 is a vulnerability in Gitea versions before 1.25.5. The issue allows deletion attempts to target tracked-time entries from another issue due to improper scoping of tracked-time entries by time ID. This vulnerability could potentially lead to unintended data modifications if exploited. Users of affected versions should apply patches to prevent potential deletion of tracked-time entries across issues.

MEDIUM Gitea CVE published 2026-07-03

CVE-2026-25779

CVE-2026-25779 is a medium-severity vulnerability in Gitea versions up to and including 1.25.4 that allows redirect bypasses through raw or percent-encoded backslashes in redirect_to values. This vulnerability exists due to improper handling of redirect_to values in Gitea, potentially allowing attackers to bypass intended redirects. Users of Gitea versions up to and including 1.25.4 should apply patches o [truncated]

CRITICAL Gitea CVE published 2026-07-03

CVE-2026-25718

Gitea versions before 1.25.5 have a vulnerability in path resolution during template repository generation. This allows template processing to read or write through symlinked or otherwise non-regular paths. The vulnerability has a CVSS score of 9.1 and is considered CRITICAL. Users of Gitea versions before 1.25.5 should review and apply patches to prevent potential path resolution issues during template r [truncated]

MEDIUM Gitea CVE published 2026-07-03

CVE-2026-25714

CVE-2026-25714 is a MEDIUM severity vulnerability in Gitea, a self-hosted Git service. The issue arises from an incomplete fix for CVE-2025-68941, where public-only token filtering is not consistently applied to the user organization API. This CVE was published on 2026-07-03T21:16:57.707Z and was last modified on 2026-07-07T18:16:36.550Z. The vulnerability has significant implications for users of Gitea v [truncated]

HIGH Gitea CVE published 2026-07-03

CVE-2026-25712

CVE-2026-25712 is a HIGH severity vulnerability with a CVSS score of 7.5. Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations. This vulnerability could potentially allow unauthorized access to sensitive information. Users should review the official CVE record and NVD details for accurate information.

HIGH Gitea CVE published 2026-07-03

CVE-2026-24690

CVE-2026-24690 is a high-severity vulnerability in Gitea, a self-hosted Git service. The issue allows unauthorized users to update or rebase pull request branches due to insufficient permission checks. This could lead to unintended changes in the codebase. Developers and administrators should review recent changes and pull requests for suspicious activity.

HIGH Gitea CVE published 2026-07-03

CVE-2026-24451

CVE-2026-24451 is a high-severity vulnerability in Gitea 1.26.2 that allows fork synchronization to continue after a parent repository changes from public to private. This can expose data to a fork that should no longer be authorized. The vulnerability has a CVSS score of 7.5 and is classified as HIGH. Affected users should review their repository configurations and update to a patched version if available.

CRITICAL Gitea CVE published 2026-07-03

CVE-2026-22547

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-03T21:16:56.890Z and has not been modified since then. Gitea versions before 1.25.5 are affected by a critical vulnerability allowing repository creation validation bypasses due to lack of validation constraints for repository creation fields. Administrators and users should prioritize updating to t [truncated]

MEDIUM Gitea CVE published 2026-07-03

CVE-2026-20909

CVE-2026-20909 is a medium-severity vulnerability in Gitea versions before 1.25.5, involving insufficient permission checks when listing tracked time entries. This issue may allow attackers to access sensitive information. Users of Gitea versions before 1.25.5 should be aware of this vulnerability and take necessary actions to upgrade to a patched version. The CVSS score is 5.3, and the severity is MEDIUM [truncated]

CRITICAL Gitea CVE published 2026-07-03

CVE-2026-20896

The CVE record indicates that Gitea Docker image versions up to and including 1.26.2 have a critical vulnerability with a CVSS score of 9.8. The vulnerability allows any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled due to the default setting of REVERSE_PROXY_TRUSTED_PROXIES=*. The CVE was published on 2026-07-03T21:16:56.660Z and last modifie [truncated]

HIGH Gitea CVE published 2026-07-03

CVE-2026-20779

CVE-2026-20779 is a HIGH severity vulnerability in Gitea, a self-hosted Git service. Versions from 1.5.0 before 1.26.3 have a defect in the Time-Based One-Time Password (TOTP) single-use enforcement. This defect allows a valid TOTP code, used for two-factor authentication, to be accepted more than once across different authentication flows, including web two-factor authentication and the Basic Auth X-Gite [truncated]

CRITICAL Gitea CVE published 2026-01-22

CVE-2026-20912

CVE-2026-20912 is a critical vulnerability in Gitea, a popular open-source software development platform. The issue arises from Gitea's improper validation of repository ownership when linking attachments to releases. This flaw could potentially allow an attachment uploaded to a private repository to be linked to a release in a different public repository, making it accessible to unauthorized users. The v [truncated]

CRITICAL Gitea CVE published 2026-01-22

CVE-2026-20897

CVE-2026-20897 is a critical vulnerability in Gitea, a popular open-source Git repository manager. The issue arises from Gitea's improper validation of repository ownership when deleting Git LFS (Large File Storage) locks. This flaw allows a user with write access to one repository to potentially delete LFS locks belonging to other repositories, which could lead to data integrity issues and unauthorized a [truncated]

HIGH Gitea CVE published 2026-01-22

CVE-2026-20736

CVE-2026-20736 is a HIGH-severity vulnerability in Gitea, a popular open-source software development platform. The issue arises from Gitea's improper verification of repository context when deleting attachments. Specifically, a user who previously uploaded an attachment to a repository may still be able to delete it after losing access to that repository by making the request through a different repositor [truncated]