Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-1058

52
FAUCET Score

CVE-2022-1058 is an Open Redirect vulnerability affecting Gitea versions prior to 1.16.5, specifically occurring during the login process. With a CVSS score of 6.1 (Medium), this vulnerability allows an attacker to redirect users to arbitrary malicious websites, potentially leading to phishing or credential theft, requiring user interaction but no authentication. While there is no evidence of active exploitation or Metasploit modules, Nuclei templates exist, and the vulnerability has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.16.5CPE matchmatch criteria
cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.2HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
2.7
CvssVersion
3.0

Exploit Intelligence

EPSS Score
50.69%
Probability of exploitation in next 30 days
EPSS Percentile
98.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Nuclei: CVE-2022-1058 · Mar 31, 2023
This CVE's current EPSS score of 0.5069 is in the 100th percentile among its peer group of 26,219 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

audiobookshelfpatch availablevia llm_extracted
axispatch availablevia llm_extracted
extreme_networkspatch availablevia llm_extracted
freebsdpatch availablevia llm_extracted
github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: code.gitea.io/giteaFixed in: 1.16.5
trendmicropatch availablevia llm_extracted

Vendor Advisories (6)

goGHSA-4rqq-rxvc-v2rcmedium

Gitea Open Redirect

Mar 25, 2022
trendmicrollm-trendmicro-f7cd19d916b0188b

Open Redirect

axisllm-axis-2ea66635c69d2170

Open Redirect

audiobookshelfllm-audiobookshelf-bc5c9a41ae267a34

Open Redirect

freebsdllm-freebsd-559ff186e0be80a0

Open Redirect

extreme_networksllm-extreme_networks-2a183508cfb3688d

Open Redirect

References

github.com / go-gitea/gitea/commit/e3d8e92bdc67562783de9a76b5b7842b68daeb48
PatchThird Party Advisory
huntr.dev / bounties/4fb42144-ac70-4f76-a5e1-ef6b5e55dc0d
ExploitPatchThird Party Advisory