code.gitea.io/gitea
Go104 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting code.gitea.io/giteapage 3 of 3
- CVE-2026-58511LOWCVSS 2.7EG 2.7✓ Fixed in 1.27.02026-07-21
Gitea: Webhook Authorization Header Returned in Plaintext via API ## Summary The `ToHook()` function in `services/webhook/general.go` decrypts the webhook's `HeaderAuthorizationEncrypted` field and returns the plaintext authorization hea…
- CVE-2026-59763MEDIUMEG 0.0✓ Fixed in 1.27.02026-07-21
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads ## Summary Hello Gitea Security Team, Thank you for your continued work on Gitea. I would like to responsibly report a potential avail…
- CVE-2026-59765MEDIUMEG 0.0✓ Fixed in 1.27.02026-07-21
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata ### Summary Gitea has robust SSRF protection via `hostmatcher.NewDialContext()` for webhook and migration clone URLs, which valida…
- CVE-2026-59766MEDIUMCVSS 4.3EG 4.3✓ Fixed in 1.27.02026-07-21
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` ## Summary CVE-2026-20800 fixed private-info leakage to revoked…
Check whether code.gitea.io/gitea is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for code.gitea.io/gitea CVEs against the assets you own.
Start Free Scan →