pkg:Go/gitea.dev
8 total CVEsHIGH1MEDIUM3
✅ Check your installed version
All known vulnerabilities
HIGH7.1CVE-2026-28740Gitea: Git LFS object reuse allows non-Code access to authorize private source objects from 0, < 1.26.3
MEDIUM6.8CVE-2026-58440Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content from 0, < 1.27.0
MEDIUM6.3CVE-2026-58416Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) from 0, < 1.27.0
MEDIUM4.3Gitea: Public-only API token restriction is not enforced on team API routes
from 0, < 1.27.0
—Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
from 0, < 1.27.0
—Gitea: Local File Inclusion via file:// URI in Migration Restore
from 0, < 1.27.0
—Gitea: REST API exposes organization membership of private organizations to public
from 0, < 1.27.0
—Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
from 0, < 1.27.0