[UPDATE] [high] Gitea: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Gitea to gain elevated privileges, impersonate users, bypass security measures, manipulate data, and disclose confidential information.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to gain elevated privileges and manipulate data.
- Who is affected
- Deployments of Gitea.
- Urgency
- Remediation is high urgency due to the potential for exploitation.
- Action
- Update to the latest version of Gitea.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Gitea
Get an email when a new Gitea advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2027
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-207790.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-208962.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 85% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-228740.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-244510.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-250380.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-277610.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-277750.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-287400.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20779 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20896 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-22874 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-24451 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-25038 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-27761 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-27775 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-28740 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highGHSA-gx3v-q759-g323: Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OT…ghsa
- highGHSA-v73x-hx65-6pf4: Gitea: Unauthorized Access to Labels of Private Organizationsghsa
- highGHSA-649p-mmhf-85c7: Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Writ…ghsa
- highGHSA-wrf9-r3h7-7x5v: Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Priv…ghsa
- mediumGHSA-3pww-vcvm-3gmj: Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints le…ghsa
- highGHSA-2m9v-5q2g-58vq: Gitea: Git LFS object reuse allows non-Code access to authorize private source objectsghsa
- criticalGHSA-f75j-4cw6-rmx4: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impers…ghsa
- criticalGHSA-2r5c-gw76-rh3w: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filterghsa
- highCVE-2026-28740: Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private sour…nvd
- highCVE-2026-27775: Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-…nvd
- mediumCVE-2026-27761: Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypa…nvd
- highCVE-2026-25038: Gitea 1.26.2 allows unauthorized users to access labels of private organizations.nvd
Recent advisories for Gitea
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownexploitedGitea security advisory (AV26-845)cccs · 2026-08-25
- criticalexploitedCVE-2026-60004: Gitea Code Injection Vulnerabilitycisa-kev · 2026-08-25
- high[UPDATE] [high] Gitea: Vulnerability allows bypassing of security measurescert-bund · 2026-08-21
- high[NEW] [high] Gitea: Multiple vulnerabilitiescert-bund · 2026-08-17
- medium[NEW] [medium] Gitea: Multiple Vulnerabilities Enable Information Disclosurecert-bund · 2026-08-14
- high[NEW] [high] Gitea: Multiple vulnerabilitiescert-bund · 2026-08-14
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25