| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Local File Inclusion via file:// URI in Migration Restore |
| REST API exposes organization membership of private organizations to public |
| Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration |
| The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked read:user-scoped token can therefore mint a registration token and register a malicious Actions runner that executes workflow jobs with access to repository secrets and source code. |
| Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim |
| Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints to reach internal services, cloud instance-metadata endpoints, or read local files such as the application configuration containing database credentials and signing secrets, with exfiltrated content persisted as migration release assets for later retrieval. |
| OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) |
| Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) |
| Gitea SSH Key Parser Denial of Service |
| GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private |
| Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint |
| Gitea Remember-Me Token Theft Not Invalidating Attacker Session |
| Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 |
| Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads |
| Webhook Authorization Header Returned in Plaintext via API |
| Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs |
| Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload |
| Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes |
| Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag |
| Privilege Escalation via Access Token Scope Escalation in API |