httpcache

package

Versions in this module

v1
Apr 7, 2026 GO-2025-4261 +1 more
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Jun 21, 2026 GO-2025-4261 +1 more
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Jun 20, 2026 GO-2025-4261 +5 more
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
May 20, 2026 GO-2025-4261 +15 more
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Apr 24, 2026 GO-2025-4261 +24 more
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Apr 18, 2026 GO-2025-4261 +24 more
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Apr 8, 2026 GO-2025-4261 +28 more
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5286: Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Sep 24, 2025 GO-2025-4261 +28 more
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5286: Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Mar 13, 2026 GO-2025-4261 +28 more
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5286: Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Jan 22, 2026 GO-2025-4261 +38 more
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5286: Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Dec 18, 2025 GO-2025-4261 +47 more
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5286: Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Nov 22, 2025 GO-2025-4261 +47 more
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5286: Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Nov 4, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5286: Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Oct 29, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5286: Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Sep 25, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Apr 28, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Oct 25, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Sep 11, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Aug 13, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Aug 4, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jul 15, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jun 20, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jun 19, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jun 10, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Apr 29, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Dec 16, 2024 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
May 12, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Apr 7, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Mar 24, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Mar 4, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Feb 19, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Feb 6, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Feb 5, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jan 10, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jan 9, 2025 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6046: Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Dec 17, 2024 GO-2025-4258 +48 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Mar 28, 2024 GO-2025-4258 +48 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Dec 13, 2024 GO-2025-4258 +48 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Dec 11, 2024 GO-2025-4258 +48 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Nov 25, 2024 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Oct 9, 2024 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-5721: Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Sep 5, 2024 GO-2025-4258 +49 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jul 4, 2024 GO-2025-4258 +51 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
May 27, 2024 GO-2024-3056 +52 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6060: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Apr 27, 2024 GO-2024-3056 +51 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Mar 28, 2024 GO-2024-3056 +51 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Sep 20, 2023 GO-2024-3056 +51 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Apr 16, 2024 GO-2024-3056 +51 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Mar 25, 2024 GO-2024-3056 +51 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Mar 22, 2024 GO-2024-3056 +51 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Mar 13, 2024 GO-2024-3056 +51 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Feb 26, 2024 GO-2024-3056 +52 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Feb 22, 2024 GO-2024-3056 +52 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Feb 1, 2024 GO-2024-3056 +52 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jan 17, 2024 GO-2024-3056 +52 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Dec 21, 2023 GO-2024-3056 +52 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Dec 12, 2023 GO-2024-3056 +52 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Nov 26, 2023 GO-2024-3056 +53 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Nov 14, 2023 GO-2024-3056 +53 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Oct 19, 2023 GO-2024-3056 +53 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Oct 6, 2023 GO-2024-3056 +53 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Sep 20, 2023 GO-2024-3056 +53 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jun 7, 2023 GO-2024-3056 +53 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Nov 26, 2023 GO-2024-3056 +53 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Oct 3, 2023 GO-2024-3056 +53 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Sep 8, 2023 GO-2024-3056 +53 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Aug 20, 2023 GO-2024-3056 +53 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jul 29, 2023 GO-2024-3056 +53 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jul 22, 2023 GO-2024-3056 +53 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jul 16, 2023 GO-2024-3056 +54 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jun 24, 2023 GO-2024-3056 +54 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jun 23, 2023 GO-2024-3056 +54 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jun 7, 2023 GO-2024-3056 +54 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Feb 22, 2023 GO-2024-3056 +54 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jul 4, 2023 GO-2024-3056 +54 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
May 3, 2023 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Apr 27, 2023 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Apr 13, 2023 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Mar 20, 2023 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Mar 5, 2023 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Feb 22, 2023 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Oct 26, 2022 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Feb 21, 2023 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Feb 20, 2023 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jan 23, 2023 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jan 19, 2023 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jan 17, 2023 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Dec 29, 2022 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Nov 24, 2022 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Oct 25, 2022 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jun 18, 2022 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Dec 21, 2022 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Oct 15, 2022 GO-2023-1894 +55 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Sep 6, 2022 GO-2022-1065 +56 more
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Aug 18, 2022 GO-2022-1065 +57 more
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jul 30, 2022 GO-2022-1065 +57 more
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jul 19, 2022 GO-2022-1065 +57 more
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jun 20, 2022 GO-2022-1065 +57 more
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jan 19, 2022 GO-2022-1065 +57 more
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jun 21, 2022 GO-2022-1065 +57 more
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
May 16, 2022 GO-2022-0612 +59 more
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
May 2, 2022 GO-2022-0612 +59 more
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Apr 20, 2022 GO-2022-0450 +60 more
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Mar 24, 2022 GO-2022-0450 +60 more
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Mar 14, 2022 GO-2022-0450 +61 more
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Mar 3, 2022 GO-2022-0442 +63 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Feb 24, 2022 GO-2022-0442 +63 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Feb 6, 2022 GO-2022-0442 +63 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jan 30, 2022 GO-2022-0442 +63 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jan 19, 2022 GO-2022-0442 +63 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jul 15, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jan 30, 2022 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jan 14, 2022 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Dec 30, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Dec 21, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Dec 2, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Oct 28, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Oct 21, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Oct 8, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Sep 20, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Sep 3, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Sep 2, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Aug 22, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Aug 6, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jul 22, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jul 15, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Mar 19, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Sep 2, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Aug 5, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jul 16, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jul 6, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Jun 18, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
May 9, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Apr 16, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Apr 11, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Mar 23, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Mar 20, 2021 GO-2022-0442 +64 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Alert  GO-2026-4274: Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea
Alert  GO-2026-4362: Gitea improperly exposes issue and pull request titles in code.gitea.io/gitea
Alert  GO-2026-4363: Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Alert  GO-2026-4364: Gitea does not properly validate repository ownership when linking attachments to releases in code.gitea.io/gitea
Alert  GO-2026-4365: Gitea may send release notification emails for private repositories to users whose access has been revoked in code.gitea.io/gitea
Alert  GO-2026-4366: Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
Alert  GO-2026-4367: Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Alert  GO-2026-4368: Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Alert  GO-2026-4369: Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Alert  GO-2026-4370: Gitea does not properly validate project ownership in organization project operations in code.gitea.io/gitea
Alert  GO-2026-5081: Gitea: Missing repository-unit authorization on issue-template API endpoints in code.gitea.io/gitea
Alert  GO-2026-5091: Gitea has insecure default SSH settings in code.gitea.io/gitea
Alert  GO-2026-5243: Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw in code.gitea.io/gitea
Alert  GO-2026-5299: Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication in code.gitea.io/gitea
Alert  GO-2026-5321: Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens in code.gitea.io/gitea
Alert  GO-2026-5334: Gitea: Token scope bypass on web archive download endpoint in code.gitea.io/gitea
Alert  GO-2026-5365: Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration in code.gitea.io/gitea
Alert  GO-2026-5448: Gitea: Open Redirect via redirect_to in code.gitea.io/gitea
Alert  GO-2026-5510: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo in code.gitea.io/gitea
Alert  GO-2026-6017: Gitea has insufficient permission checks for Composer package source links in code.gitea.io/gitea
Alert  GO-2026-6029: Gitea: Git LFS object reuse allows non-Code access to authorize private source objects in code.gitea.io/gitea
Alert  GO-2026-6030: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter in code.gitea.io/gitea
Alert  GO-2026-6031: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data in code.gitea.io/gitea
Alert  GO-2026-6041: Gitea: Notification API leaks private issue metadata after access revocation in code.gitea.io/gitea
Alert  GO-2026-6043: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write in code.gitea.io/gitea
Alert  GO-2026-6044: Gitea: Permanent Fork PR Workflow Approval Gate Bypass in code.gitea.io/gitea
Alert  GO-2026-6051: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` in code.gitea.io/gitea
Alert  GO-2026-6056: Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts in code.gitea.io/gitea
Alert  GO-2026-6057: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface in code.gitea.io/gitea
Alert  GO-2026-6074: Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions in code.gitea.io/gitea
Alert  GO-2026-6075: Gitea: SSRF via HTTP Redirect in Repository Migration in code.gitea.io/gitea
Alert  GO-2026-6076: Gitea: Unauthorized Access to Labels of Private Organizations in code.gitea.io/gitea
Alert  GO-2026-6077: Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service in code.gitea.io/gitea
Alert  GO-2026-6080: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea
Alert  GO-2026-6081: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private in code.gitea.io/gitea
Alert  GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Alert  GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Alert  GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Alert  GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Alert  GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Alert  GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Alert  GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Alert  GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Alert  GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Alert  GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL