[NEW] [high] Gitea: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Gitea to execute arbitrary code, gain elevated permissions, bypass security measures, manipulate data, disclose sensitive information, hijack or reuse sessions, or trigger a denial-of-service state.
CSIRTS triage
- What
- Multiple vulnerabilities in Gitea can be exploited by an attacker to execute arbitrary code, gain elevated permissions, bypass security measures, manipulate data, disclose sensitive information, hijack sessions, or trigger a denial-of-service state.
- Who is affected
- Attackers targeting systems running the affected versions of Gitea.
- Urgency
- Remediation is high urgency due to the wide range of potential impacts including remote code execution and privilege escalation.
- Action
- Update to the latest version of Gitea.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Gitea
Get an email when a new Gitea advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2304
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-236030.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-429310.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-501050.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-544810.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-559820.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-559840.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-559860.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-559870.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-564430.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-566540.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Gitea: Multiple Vulnerabilities Enable Information Disclosurecert-bund
- highCVE-2026-59765: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metad…nvd
- mediumCVE-2026-59763: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploadsnvd
- lowCVE-2026-58511: Webhook Authorization Header Returned in Plaintext via APInvd
- mediumCVE-2026-58510: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path r…nvd
- criticalCVE-2026-58508: Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)nvd
- mediumCVE-2026-58507: Private Repository Existence Disclosure via go-get Meta Endpointnvd
- lowCVE-2026-58445: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel APInvd
- mediumCVE-2026-58444: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{rep…nvd
- criticalCVE-2026-58443: Public-only repository tokens can update private PR head branchesnvd
- mediumCVE-2026-58442: Repository migration SSRF via multi-answer DNS allow-list bypassnvd
- mediumCVE-2026-58441: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURLnvd
Recent advisories for Gitea
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalexploitedGHSA-rcr6-4jqh-j84m: Gitea: Remote Code Execution via diffpatch Git Hook Installationghsa · 2026-09-08
- high[NEW] [high] Gitea: Multiple vulnerabilities allow execution of arbitrary codecert-bund · 2026-08-31
- highexploited[NEW] [high] Gitea: Vulnerability allows code executioncert-bund · 2026-08-27
- criticalexploitedCVE-2026-60004: Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook instal…nvd · 2026-08-26
- high[NEW] [high] Gitea: Vulnerability enables Security Bypasscert-bund · 2026-08-26
- unknownexploitedGitea security advisory (AV26-845)cccs · 2026-08-25
More from CERT-Bund (BSI) Security Advisories
- high[UPDATE] [hoch] Red Hat Enterprise Linux (postgis, virtuoso-opensource): Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Red Hat Enterprise Linux: Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-11
- high[UPDATE] [hoch] OpenSSL: Mehrere Schwachstellen2026-09-11