Gitea Limited maintains a self-hosted Git service platform that, despite a narrow product footprint, occupies a prominent position among development infrastructure tools and is widely deployed across organizations seeking on-premises version control. Vulnerabilities affecting Gitea skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the platform's role as a trusted authentication and repository gateway. The exposure recurs through access-control and input-validation weakness classes—including improper access control, cross-site scripting, and authorization bypass flaws—that are characteristic of web applications handling sensitive code and credentials. Defenders should prioritize Gitea advisories for internet-exposed instances and treat authentication and authorization patches as urgent, since compromised repositories can affect entire development pipelines; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gitea Limited over time
Of all the CVEs published by Gitea Limited as a CNA, 18.0% affect products that Gitea Limited develops as a vendor.
Of all the CVEs published that affect products developed by Gitea Limited, 17.3% are self-published by Gitea Limited as a CNA.
Signals from CVEs in this vendor scope (52 CVEs).
52 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-14144HIGH The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the documentation was not understood (e.g., on | Oct 16, 2020 | 7.2 | 87 | NO | YES |
CVE-2022-30781HIGH Gitea before 1.16.7 does not escape git fetch remote. | May 16, 2022 | 7.5 | 86 | NO | YES |
CVE-2019-11229HIGH models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution. | Apr 15, 2019 | 8.8 | 70 | NO | YES |
CVE-2022-1058MEDIUM Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5. | Mar 24, 2022 | 6.1 | 52 | NO | YES |
CVE-2026-20912CRITICAL Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release | Jan 22, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-20897CRITICAL Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other rep | Jan 22, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-20750CRITICAL Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging | Jan 22, 2026 | 9.1 | 35 | NO | NO |
CVE-2022-42968CRITICAL Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. | Oct 16, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-45328MEDIUM Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs. | Feb 8, 2022 | 6.1 | 31 | NO | YES |
CVE-2021-45327CRITICAL Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user ex | Feb 8, 2022 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (52 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gitea Limited.
Media articles that mention a CVE ID that affects a product developed by Gitea Limited — matched by CVE ID, not by vendor name.