PatchSiren

Gitea CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Gitea CVE published 2026-08-13

CVE-2026-59765

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T17:17:30.493Z and has not been modified since then. This Server-Side Request Forgery (SSRF) vulnerability via Migration Asset Downloads bypasses hostmatcher in Gitea, potentially allowing reads of internal files and cloud metadata. The vulnerability affects Gitea installations prior to version 1. [truncated]

MEDIUM Gitea CVE published 2026-08-13

CVE-2026-59763

The CVE-2026-59763 vulnerability involves unbounded Arch package file metadata, which can cause resource amplification in Gitea package uploads. This issue has a CVSS score of 4.3 and is classified as MEDIUM severity. Gitea users and administrators should review package upload configurations to validate Arch package file metadata handling, implement compensating controls to monitor and limit resource usag [truncated]

LOW Gitea CVE published 2026-08-13

CVE-2026-58511

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T17:17:28.973Z and has not been modified since then. CVE-2026-58511 is a low-severity vulnerability (CVSS score of 2.7) related to the return of a webhook authorization header in plaintext via an API. The affected product and vendor are not explicitly stated, but there is a potential connection to [truncated]

MEDIUM Gitea CVE published 2026-08-13

CVE-2026-58510

The CVE-2026-58510 vulnerability is related to the ClearRepoWatches fix not being applied to the API EditRepo path in Gitea, potentially leading to stale watches on public->private repositories. This issue has a medium severity with a CVSS score of 4.3. Organizations and administrators using Gitea should be aware of this vulnerability and take necessary actions to mitigate potential risks. The CVE record [truncated]

CRITICAL Gitea CVE published 2026-08-13

CVE-2026-58508

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T17:17:28.757Z and has not been modified since then. The CVE record indicates two SSRF vulnerabilities in Gitea migration/mirror, specifically DNS rebinding and missing re-validation. These vulnerabilities have a CVSS score of 9.1 and are considered critical. Organizations using Gitea should prior [truncated]

MEDIUM Gitea CVE published 2026-08-13

CVE-2026-58507

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T17:17:28.653Z and has not been modified since then. This vulnerability, CVE-2026-58507, is a Private Repository Existence Disclosure via the go-get Meta Endpoint in Gitea. It has a CVSS score of 5.3 and is classified as MEDIUM severity. The vulnerability affects Gitea instances, and defenders sho [truncated]

LOW Gitea CVE published 2026-08-13

CVE-2026-58445

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T17:17:28.543Z and has not been modified since then. This vulnerability, CVE-2026-58445, is a low-severity issue found in Gitea's unscoped DeleteIssueLabel API, which could potentially allow cross-repository label-ID enumeration. The vulnerability has a CVSS score of 2.7, indicating limited impact [truncated]

MEDIUM Gitea CVE published 2026-08-13

CVE-2026-58444

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T17:17:28.437Z and has not been modified since then. CVE-2026-58444 is a medium-severity vulnerability in Gitea related to personal access token scope enforcement bypass on the repository home page, potentially disclosing private repository contents. This vulnerability affects Gitea deployments, a [truncated]

MEDIUM Gitea CVE published 2026-08-13

CVE-2026-58441

A potential Server-Side Request Forgery (SSRF) vulnerability exists in the restore-repo functionality of Gitea instances or similar products due to unsanitized input from pull_request.yml Head.CloneURL. This could allow an attacker to manipulate requests made by the server, potentially leading to unauthorized access or data breaches. The vulnerability was reported and verified through official channels, b [truncated]

MEDIUM Gitea CVE published 2026-08-13

CVE-2026-58440

The CVE-2026-58440 vulnerability, classified as medium-severity with a CVSS score of 6.8, affects Gitea, a self-hosted Git service. This vulnerability is related to the `DeleteCollaboration` function, which fails to properly clean up webhooks created by collaborators when their repository access is revoked. This allows for ongoing real-time exfiltration of private repository content. Gitea administrators [truncated]

HIGH Gitea CVE published 2026-08-13

CVE-2026-58439

CVE-2026-58439 is a high-severity vulnerability in Gitea, a self-hosted Git service. The vulnerability allows for branch protection bypass via PR retargeting, preserving stale 'official' approval flags. This could potentially allow attackers to bypass branch protection rules and push unauthorized changes to protected branches. The CVSS score is 8.1, indicating a high severity level. The vulnerability was [truncated]

HIGH Gitea CVE published 2026-08-13

CVE-2026-58438

CVE-2026-58438 is a Cross-repository IDOR vulnerability in Gitea, allowing attackers to tamper with and comment on private repositories they cannot access. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. Gitea released version 1.27.0, which addresses this issue. Organizations and users of Gitea, especially those hosting private repositories, should be aware of this vulnerabil [truncated]

HIGH Gitea CVE published 2026-08-13

CVE-2026-58437

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T17:17:27.703Z and has not been modified since then. CVE-2026-58437 is a high-severity vulnerability in Gitea, allowing for repository visibility manipulation via Git push options. The CVSS score is 7.1. This vulnerability affects Gitea users and administrators, who should be aware of this vulnera [truncated]

MEDIUM Gitea CVE published 2026-08-13

CVE-2026-58435

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T17:17:27.490Z and has not been modified since then. This medium-severity vulnerability in Gitea LFS Deploy-Key allows for privilege escalation with a CVSS score of 5.4. Gitea instance administrators and security teams should review configurations, implement monitoring, and apply vendor remediatio [truncated]

HIGH Gitea CVE published 2026-08-13

CVE-2026-58434

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T17:17:27.377Z and has not been modified since then. The CVE-2026-58434 vulnerability in Gitea allows private repository metadata to remain accessible after access revocation. This issue has a CVSS score of 7.5 and HIGH severity, related to CWE-200 and CWE-862. Affected Gitea users should verify t [truncated]

CRITICAL Gitea CVE published 2026-08-13

CVE-2026-58433

The CVE-2026-58433 vulnerability in Gitea's team-repository linking endpoint allows unauthorized access, bypassing the RepoAdminChangeTeamAccess organization setting. This critical vulnerability has a CVSS score of 9.1 and requires immediate attention from Gitea administrators. Affected Gitea deployments should be identified and verified for exposure. The vulnerability class involves improper access contr [truncated]

MEDIUM Gitea CVE published 2026-08-13

CVE-2026-58432

CVE-2026-58432 involves multiple vulnerabilities in Gitea, including CWE-200, CWE-639, CWE-732, and CWE-862. The CVSS score is 5.9 with AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N. This vulnerability affects Gitea instances, potentially exposing sensitive information and allowing unauthorized access. Users and administrators should review their Gitea deployments and consider applying patches or updates.

MEDIUM Gitea CVE published 2026-08-13

CVE-2026-58431

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T17:17:27.050Z and has not been modified since then. CVE-2026-58431 is a MEDIUM-severity vulnerability in an unknown vendor's product, potentially allowing limited impact due to public-only API token restriction not being enforced on team API routes. The CVSS score is 4.3. The vulnerability affect [truncated]

MEDIUM Gitea CVE published 2026-08-13

CVE-2026-58428

CVE-2026-58428 is a medium severity vulnerability in Gitea, a variant of CVE-2025-68939, allowing for a release attachment extension allowlist bypass via the web release edit form. The CVSS score is 6.5, with AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N. Gitea users are advised to verify their installations and ensure they are running the latest version. This vulnerability could potentially allow attackers to bypa [truncated]

HIGH Gitea CVE published 2026-08-13

CVE-2026-58427

CVE-2026-58427 is a high-severity vulnerability in Gitea, a self-hosted Git service. The issue arises from an incomplete fix for PR #38145, which fails to properly restrict access to private organization member lists through the /members API endpoint. This allows unauthorized users to potentially access sensitive information about organization members. The vulnerability has a CVSS score of 7.5 and is clas [truncated]

MEDIUM Gitea CVE published 2026-08-13

CVE-2026-58425

CVE-2026-58425 is a medium-severity vulnerability affecting Gitea's OAuth token introspection functionality. The vulnerability causes the server to return metadata of tokens issued to other clients, violating RFC 7662 section 4. This could potentially allow unauthorized parties to gain information about other clients' tokens. The vulnerability is addressed in Gitea version 1.27.0. Administrators and users [truncated]

MEDIUM Gitea CVE published 2026-08-13

CVE-2026-58420

The CVE-2026-58420 vulnerability is a local file inclusion via file:// URI in Migration Restore in Gitea, with a CVSS score of 4.4, indicating medium severity. Gitea users and administrators should be aware of this vulnerability and take steps to patch or mitigate it. The vulnerability requires local access and a high privilege level to exploit. However, details are limited, and further verification is ne [truncated]

HIGH Gitea CVE published 2026-08-13

CVE-2026-58417

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T17:17:26.410Z and has not been modified since then. CVE-2026-58417 is a high-severity vulnerability in Gitea's REST API, potentially allowing public exposure of private organization memberships. The vulnerability has a CVSS score of 7.5 and is classified as CWE-284. Gitea instance administrators [truncated]

HIGH Gitea CVE published 2026-08-13

CVE-2026-58416

CVE-2026-58416 is a high-severity vulnerability in Gitea, a collaborative development platform. The vulnerability allows a Fork-PR Actions task to read a third private repository via the collaborative-owner branch due to a missing fork-PR guard. This could potentially allow unauthorized access to sensitive information in private repositories. Gitea users and administrators should be aware of this vulnerab [truncated]

HIGH Gitea CVE published 2026-08-13

CVE-2026-58314

CVE-2026-58314 reports two Server-Side Request Forgery (SSRF) findings in Gitea 1.26.2, a high-severity vulnerability with a CVSS score of 7.7. Organizations using Gitea 1.26.2 should be aware of these vulnerabilities and prioritize upgrading to a patched version. The CVE record provides limited information, but references to Gitea's release announcement, release notes, and a GitHub advisory are available [truncated]

MEDIUM Gitea CVE published 2026-08-13

CVE-2026-57897

CVE-2026-57897 is a medium-severity vulnerability in Gitea, a cross-repo information disclosure via org-level actions run/job APIs. The vulnerability has a CVSS score of 6.5 and is classified under CWE-200 and CWE-863. Affected organizations should prioritize patching to prevent potential information disclosure. The vulnerability allows unauthorized access to sensitive information across repositories, pot [truncated]

MEDIUM Gitea CVE published 2026-08-13

CVE-2026-57886

CVE-2026-57886 is a MEDIUM-severity vulnerability in Gitea that allows cross-repository issue/comment attachment re-linking, potentially exposing private attachment content. The vulnerability is addressed in Gitea version 1.27.0. Administrators and users of Gitea instances should be aware of this vulnerability and take steps to mitigate it. The CVE record was published on 2026-08-13T17:17:25.863Z and has [truncated]

MEDIUM Gitea CVE published 2026-08-13

CVE-2026-56657

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T17:17:25.470Z and has not been modified since then. The NVD entry is currently Deferred. This vulnerability affects Gitea instances through a potential Denial of Service in the SSH Key Parser, with a CVSS score of 6.2 and a severity of MEDIUM. Administrators and users should review and verify the [truncated]

CRITICAL Gitea CVE published 2026-08-13

CVE-2026-56654

CVE-2026-56654 is a critical vulnerability in Gitea's API, allowing for privilege escalation via access token scope escalation. The vulnerability has a CVSS score of 9.8 and is classified under CWE-284. Affected organizations, especially those with exposed Gitea instances or integrations with other critical systems, should be aware of this vulnerability and take immediate action to verify their inventory [truncated]

CRITICAL Gitea CVE published 2026-08-13

CVE-2026-56443

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T17:17:25.247Z and has not been modified since then. This critical vulnerability, CVE-2026-56443, is a potential token public-only scope bypass vulnerability in Gitea, residual after CVE-2026-25714 / PR #37118. It affects Limited-visibility owners in Repository and Package categories, potentially [truncated]