Gitea Limited

First CVE: Aug 6, 2024Active for: 2 years
50
CVEs Published
More CVEs Published than 58% of tracked CNAs
25.0
Avg CVEs / Year
More Avg CVEs / Year than 73% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 75% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Gitea Limited as a CNA, 18.0% affect products that Gitea Limited develops as a vendor.

18.0%
82.0%
Self-reported: 9Third-party: 41

Of all the CVEs published that affect products developed by Gitea Limited, 17.3% are self-published by Gitea Limited as a CNA.

17.3%
82.7%
Self-published: 9Published by other CNAs: 43

Trends Over Time

The number and severity of CVEs published by Gitea Limited over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2024
23 months ago
Most Recent CVE
Jul 3, 2026
21 days ago

Top CVEs

All CVEs published by Gitea Limited as a CNA, regardless of affected vendor or product.

50 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
Jul 3, 20268.273NOYES
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects
Aug 6, 202410.059NOYES
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authenticatio
Jul 3, 20269.851NONO
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
Jul 3, 20269.642NONO
Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
Jul 3, 20269.642NONO
Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
Jul 3, 20269.840NONO
Permanent Fork PR Workflow Approval Gate Bypass
Jul 3, 20268.939NONO
Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.
Jul 3, 20269.838NONO
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
Jul 3, 20269.137NONO
Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer.
Jul 3, 20268.736NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA50 CVEs
Severity distribution among all CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network50 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low49 (98.0%)
High1 (2.0%)
Unknown0 (0.0%)
User Interaction
None45 (90.0%)
Unknown0 (0.0%)
Required5 (10.0%)
Privileges Required
Low20 (40.0%)
High0 (0.0%)
None30 (60.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (50 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
4.0% of CVEs· 91st percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Gitea Limited as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Gitea Limited as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs