Skip to content
Threat Feed

Product

Gitea

8 briefs RSS
high advisory

Critical RCE and Information Disclosure Vulnerability in Gitea

Gitea contains a critical vulnerability allowing remote, unauthenticated attackers to execute arbitrary code and gain unauthorized access to sensitive information.

Gitea +1 vulnerability remote-code-execution web-application
1t 1c updated
high threat

Gitea Remote Code Execution Vulnerability

A vulnerability in Gitea allows a remote, unauthenticated attacker to execute arbitrary code, which could lead to full compromise of the affected Gitea instance and potentially the underlying server.

exploited Gitea vulnerability rce
1t
critical advisory

Gitea Docker Images Insecure Default Allows User Impersonation via X-WEBAUTH-USER

Gitea Docker images ship with a critical misconfiguration, CVE-2026-20896, where `REVERSE_PROXY_TRUSTED_PROXIES = *` by default, enabling any client to bypass authentication and impersonate users via the `X-WEBAUTH-USER` HTTP header when reverse proxy authentication is enabled, leading to unauthorized access to user accounts, including administrative ones.

PoC gitea/gitea Docker images +1 misconfiguration authentication-bypass docker gitea web-application cve
1r 2t 1c updated
high advisory

Gitea Repository Migration SSRF and Internal Git Repository Exfiltration

A critical vulnerability in Gitea allows an authenticated, low-privileged user to exfiltrate internal Git repositories by exploiting a validation bypass, where Gitea's initial URL validation for repository migration is circumvented by the Git command-line client's default behavior of following HTTP redirects to otherwise blocked internal IP addresses, leading to server-side request forgery (SSRF) and the theft of sensitive code, credentials, and configuration into an attacker-controlled repository, with persistent exfiltration possible through pull mirrors.

Gitea +1 server-side-request-forgery ssrf vulnerability code-exfiltration data-exfiltration information-disclosure api-vulnerability web-vulnerability +5
2r 9t 1c
medium advisory

Gitea: Multiple Vulnerabilities

An anonymous, remote attacker can exploit multiple vulnerabilities in Gitea to manipulate data or trigger a denial of service.

Gitea vulnerability denial-of-service data-manipulation
2t updated
high advisory

Gitea: Multiple Vulnerabilities Leading to XSS, Info Disclosure, and File Manipulation

An attacker can exploit multiple unpatched vulnerabilities in Gitea to bypass security measures, disclose sensitive information, perform Cross-Site Scripting (XSS) attacks, and manipulate files, posing a high risk to self-hosted Git instances.

Gitea web-exploitation vulnerability
4t
high advisory

Gitea Security Bypass Vulnerability

A remote, unauthenticated attacker can exploit a vulnerability in Gitea to bypass existing security measures, potentially leading to unauthorized access, privilege escalation, or data manipulation within the application.

Gitea vulnerability web-application defense-evasion
1t
medium advisory

Gitea Unauthenticated Container Registry Access (CVE-2026-27771)

A vulnerability in Gitea's built-in container registry (CVE-2026-27771) allows unauthenticated attackers to pull private container images, potentially exposing source code, secrets, and production infrastructure details, affecting over 30,000 deployments.

Gitea +2 vulnerability container registry access control cloud git
2r 1t 1c 2i updated