Security: go-gitea/gitea
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)GHSA-25gq-j9jx-43pg published
Jul 13, 2026 by bircniModerate -
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routesGHSA-wrr5-99h5-gq57 published
Jun 14, 2026 by lunnyHigh -
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/giteaGHSA-q9pg-jj6x-j9p6 published
Jul 13, 2026 by bircniModerate -
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state writeGHSA-hg5r-vq93-9fv6 published
Jul 1, 2026 by lunnyCritical -
Webhook Authorization Header Returned in Plaintext via APIGHSA-3r5c-2xxx-h872 published
Jul 13, 2026 by bircniLow -
Git Smart HTTP Skips Repository Token Scopes for Bearer TokensGHSA-cc8w-r4qh-3v65 published
May 25, 2026 by lunnyHigh -
Unbounded Arch package file metadata can cause resource amplification in Gitea package uploadsGHSA-9mq6-mqjj-c2c5 published
Jul 13, 2026 by bircniModerate -
Critical Vulnerability - Already emailedGHSA-8qw8-rq86-9pc2 published
Jun 5, 2026 by lunnyHigh -
Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claimGHSA-x77v-q46j-393g published
Jul 13, 2026 by bircniLow -
OAuth2 access token scope enforcement bypass via HTTP Basic authenticationGHSA-9r5x-wg6m-x2rc published
Jun 5, 2026 by lunnyHigh