Gitea Limited
First CVE: Aug 6, 2024Active for: 2 years
50
CVEs Published
More CVEs Published than 58% of tracked CNAs
25.0
Avg CVEs / Year
More Avg CVEs / Year than 73% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 75% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Gitea Limited as a CNA, 18.0% affect products that Gitea Limited develops as a vendor.
18.0%
82.0%
Self-reported: 9Third-party: 41
Of all the CVEs published that affect products developed by Gitea Limited, 17.3% are self-published by Gitea Limited as a CNA.
17.3%
82.7%
Self-published: 9Published by other CNAs: 43
Trends Over Time
The number and severity of CVEs published by Gitea Limited over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2024
23 months ago
Most Recent CVE
Jul 3, 2026
21 days ago
Top CVEs
All CVEs published by Gitea Limited as a CNA, regardless of affected vendor or product.
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27771HIGH Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information. | Jul 3, 2026 | 8.2 | 73 | NO | YES |
CVE-2024-6886CRITICAL Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects | Aug 6, 2024 | 10.0 | 59 | NO | YES |
CVE-2026-20896CRITICAL Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authenticatio | Jul 3, 2026 | 9.8 | 51 | NO | NO |
CVE-2026-58426CRITICAL Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write | Jul 3, 2026 | 9.6 | 42 | NO | NO |
CVE-2026-22874CRITICAL Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering. | Jul 3, 2026 | 9.6 | 42 | NO | NO |
CVE-2026-58422CRITICAL Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts | Jul 3, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-58424HIGH Permanent Fork PR Workflow Approval Gate Bypass | Jul 3, 2026 | 8.9 | 39 | NO | NO |
CVE-2026-27780CRITICAL Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks. | Jul 3, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-26247CRITICAL Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check. | Jul 3, 2026 | 9.1 | 37 | NO | NO |
CVE-2026-28737HIGH Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer. | Jul 3, 2026 | 8.7 | 36 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA50 CVEs
24%
44%
30%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network50 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low49 (98.0%)
High1 (2.0%)
Unknown0 (0.0%)
User Interaction
None45 (90.0%)
Unknown0 (0.0%)
Required5 (10.0%)
Privileges Required
Low20 (40.0%)
High0 (0.0%)
None30 (60.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (50 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
4.0% of CVEs· 91st percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Gitea Limited as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Gitea Limited as a CNA — matched by CVE ID, not by organization name.