Security: go-gitea/gitea
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Git Smart HTTP Skips Repository Token Scopes for Bearer TokensGHSA-cc8w-r4qh-3v65 published
May 25, 2026 by lunnyHigh -
Unbounded Arch package file metadata can cause resource amplification in Gitea package uploadsGHSA-9mq6-mqjj-c2c5 published
Jul 13, 2026 by bircniModerate -
Critical Vulnerability - Already emailedGHSA-8qw8-rq86-9pc2 published
Jun 5, 2026 by lunnyHigh -
Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claimGHSA-x77v-q46j-393g published
Jul 13, 2026 by bircniLow -
OAuth2 access token scope enforcement bypass via HTTP Basic authenticationGHSA-9r5x-wg6m-x2rc published
Jun 5, 2026 by lunnyHigh -
Public-Only Personal access tokens scope bypass in Organization and Permission EndpointsGHSA-fq2p-5p22-8g6j published
Jul 13, 2026 by bircniModerate -
Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repoGHSA-mm7c-rhg6-qr4r published
Jun 5, 2026 by lunnyHigh -
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval FlagGHSA-w5pg-649r-p6gg published
Jul 13, 2026 by bircniHigh -
Stored XSS via glTF `extensionsRequired` in Gitea 3D File ViewerGHSA-9cpj-qc93-vw8v published
Jun 14, 2026 by lunnyHigh -
Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flawGHSA-8629-vc8r-5p58 published
Jun 5, 2026 by lunnyModerate