Security: go-gitea/gitea
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Remote Code Execution via unescaped markup `Context` into external renderer argvGHSA-579w-82gf-89m2 published
Aug 14, 2026 by bircniHigh -
Admin repository collaborator can self-escalate to Owner and transfer the repositoryGHSA-h62v-wmrr-5qjq published
Aug 14, 2026 by bircniModerate -
Jupyter notebook renderer emits attacker-controlled CSS classes into unsanitized, unsandboxed outputGHSA-7452-653r-6gp8 published
Aug 14, 2026 by bircniModerate -
2FA bypass and persistent account takeover via OpenID identity linkingGHSA-8xjr-x7rg-hp5h published
Aug 14, 2026 by bircniHigh -
Remote Code Execution via diffpatch Git Hook InstallationGHSA-rcr6-4jqh-j84m published
Jul 28, 2026 by TheFox0x7Critical -
Unauthenticated Arbitrary File Read can lead to RCEGHSA-6v53-hr58-556r published
Aug 2, 2026 by TheFox0x7Critical -
Secret Exfiltration via Reusable Workflow Resolution in pull_request_target EventsGHSA-r9ch-mqjm-g67v published
Aug 14, 2026 by bircniHigh -
WebAuthn second factor is bypassed on OAuth2/OpenID sign-in (WebAuthn-only users)GHSA-92j2-6qcg-c28c published
Aug 14, 2026 by bircniHigh -
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot accessGHSA-xv9x-fj9g-vj6h published
Jul 13, 2026 by bircniModerate -
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization settingGHSA-m6qc-j894-7h9r published
Jul 13, 2026 by bircniHigh