code.gitea.io/gitea Security Analysis
code.gitea.io/gitea has 14 known security vulnerabilities in Go Modules. Upgrade to version 1.27.0 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Low Immediate Risk
No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.
Recommended safe version: 1.27.0
Upgrading to 1.27.0 or later resolves all 14 known vulnerabilities in code.gitea.io/gitea. Run: go get code.gitea.io/gitea@v1.27.0
Is code.gitea.io/gitea in your project?
Check if you're affected and upgrade to 1.27.0 to stay secure.
Vulnerabilities
14 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2026-20896 Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` | CRITICAL | All versions | 1.26.3 |
| CVE-2026-58443 Gitea: Public-only repository tokens can update private PR head branches | CRITICAL | All versions | 1.27.0 |
| CVE-2026-58426 Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write | CRITICAL | All versions | 1.26.2 |
| CVE-2026-22874 Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter | CRITICAL | All versions | 1.26.3 |
| CVE-2024-6886 Gitea Cross-site Scripting Vulnerability | CRITICAL | All versions | 1.22.1 |
| CVE-2026-56750 Gitea Remember-Me Token Theft Not Invalidating Attacker Session | CRITICAL | All versions | 1.27.0 |
| CVE-2019-11576 Gitea Allows 1FA Even for 2FA-Enrolled Accounts | CRITICAL | All versions | 1.8.0 |
| CVE-2026-58424 Gitea: Permanent Fork PR Workflow Approval Gate Bypass | HIGH | All versions | 1.26.3 |
| CVE-2026-27775 Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write | HIGH | All versions | 1.26.3 |
| CVE-2026-56654 Gitea: Privilege Escalation via Access Token Scope Escalation in API | HIGH | All versions | 1.27.0 |
| CVE-2026-28737 Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer | HIGH | All versions | 1.26.0 |
| CVE-2026-57894 Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration | HIGH | All versions | 1.27.0 |
| CVE-2026-26231 Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo | HIGH | All versions | 1.26.2 |
| CVE-2026-27771 Gitea has insufficient permission checks for Composer package source links | HIGH | All versions | 1.26.2 |
About This Data
Vulnerability data for code.gitea.io/gitea is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related Go Modules Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of code.gitea.io/gitea.