Security: go-gitea/gitea
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Attachments created before the January 2026 cutoff skip the cross repository check entirely, and permission is then evaluated against the repository named in the URL rather than the repository owning the attachment, so a private repository's attachment is served through any public repository's pathGHSA-frpv-2xgv-wxpq published
Aug 29, 2026 by bircniModerate -
Restricted users can read limited-visibility users’ SSH and GPG keys through the APIGHSA-wwmh-7r9x-fg49 published
Aug 29, 2026 by bircniModerate -
Restricted users can read limited-visibility users' issue titles and bodies through issue searchGHSA-wg93-gp4m-c6vr published
Aug 29, 2026 by bircniHigh -
Restricted users can access limited-visibility users' activity feeds and contribution heatmaps through the APIGHSA-rfm6-r2x5-cg56 published
Aug 29, 2026 by bircniModerate -
RCE on self-hosted runners | fork-PR approval gate (`NeedApproval`) bypass via job-level concurrency cancellationGHSA-v2w8-m4gr-qj65 published
Aug 29, 2026 by bircniHigh -
Restricted users can enumerate limited-visibility organizations via the user org-list API (authorization bypass)GHSA-w4wc-g858-3672 published
Aug 29, 2026 by bircniLow -
Package registry: restricted users can read packages of limited-visibility users (authorization bypass)GHSA-px3q-x2mm-55wg published
Aug 29, 2026 by bircniModerate -
Fork pull requests can read reusable workflow files from another private repository (missed sibling of GHSA-fj8v-hjwv-qm88)GHSA-2xph-7j4g-43rg published
Aug 29, 2026 by bircniModerate -
Swift registry per-file 128KiB manifest guard bypassed by aggregationGHSA-fqxf-w92m-prvq published
Aug 29, 2026 by bircniModerate