28,679 Entries 2,229 Sources 5 Verticals Last sync 2 minutes Live
Self-hosted apps

Gitea

Gitea
v1.26.2 bewährt latest release
20.05.2026

bewährt — keine offenen Regressionen, etabliert · 0 open bugs, 0 Regressions

Upgrade assessment

Sicherheitsrelevant

Zeitnah aktualisieren

8 CVE(s) zuletzt, höchste Schwere: hoch

Derived automatically from release, repo and CVE data — no judgment by a language model.

Specsattributes
health{'open_bugs': 0, 'checked_at': '2026-06-08T02:00:40.179938', 'open_regressions': 0}
gh_etagW/"90ecbe08062136b257b61be77c5363fccffcbaea9fa7c1da6a51cc75e0b05e90"
gh_checked_at2026-06-08T03:00:00.127675+00:00
Timelinealle Einträge
Type Ereignis · Quelle Value · Time
CVE
Self-hosted apps High

Gitea uses insecure SSH configurations by default with weak encryption algorithms that are considered compromised or use outdated hash functions, compromising the security of SSH connections.

Advisory
06.06.2026
CVE
Self-hosted apps Medium

A vulnerability in Gitea allows public-only scoped API tokens to access private organization data, despite being restricted to public content only.

CVE-2026-25714
06.06.2026
CVE
Self-hosted apps High

A vulnerability in Gitea allows authenticated users with only read access to push arbitrary commits directly to repositories, bypassing all write access controls, which can lead to complete repository compromise.

CVE-2026-26231
06.06.2026
CVE
Self-hosted apps High

Gitea bypasses OAuth2 permission restrictions when tokens are submitted via HTTP Basic Authentication instead of Bearer tokens, allowing apps with limited scopes to gain write access to user profiles and repositories.

CVE-2026-28699
06.06.2026
CVE
Self-hosted apps High

CVE-2026-27771

CVE-2026-27771
06.06.2026
CVE
Self-hosted apps High

A security vulnerability in Gitea allows accessing private Git repositories with OAuth2/Bearer tokens that lack required repository permissions, because scope validation only occurs during Basic authentication but not Bearer authentication.

CVE-2026-28744
06.06.2026
CVE
Self-hosted apps Medium

A security vulnerability in Gitea allows downloading complete private repository archives using access tokens that only have permissions for other areas like issues, not repository content.

CVE-2026-20706
06.06.2026
CVE
Self-hosted apps Medium

Three API endpoints in Gitea allow users with limited permissions to read issue template and configuration files from private repositories, even though they should not have access to the code section.

CVE-2026-27783
06.06.2026
REL
Self-hosted apps Critical bewährt

Security update with fixes for permissions, token scopes, OAuth validation and various authentication issues

v1.26.2
20.05.2026
REL
Self-hosted apps Medium bewährt

Bugfix release with fixes for OAuth2 escaping, container authentication, Actions workflows, Mermaid diagrams and various UI issues

v1.26.1
24.04.2026
REL
Self-hosted apps Medium bewährt

Gitea v1.26.0 introduces breaking changes to Swagger annotations and API endpoints, new Actions features, Terraform registry, global banners and numerous performance improvements

v1.26.0
18.04.2026
REL
Self-hosted apps Medium bewährt

Gitea v1.26.0-rc0 introduces breaking changes to Swagger annotations and API endpoints, new Actions features, Terraform registry support, and numerous UI enhancements

v1.26.0-rc0
08.04.2026
REL
Self-hosted apps High bewährt

Security update fixing multiple critical vulnerabilities in OAuth2, user permissions and path resolution along with various bug fixes

v1.25.5
13.03.2026
REL
Self-hosted apps High bewährt

Security update with fixes for repository permissions, attachments, LFS locks and various authentication issues

v1.25.4
22.01.2026
REL
Self-hosted apps Medium bewährt

Security update with Go 1.25.5, markdown editor improvements and fixes for various bugs in SSH cloning, email handling and pull requests

v1.25.3
18.12.2025
REL
Self-hosted apps High bewährt

Security update with cryptography library upgrade and fixes for various permission and login bugs plus numerous bugfixes

v1.25.2
22.11.2025
REL
Self-hosted apps Medium bewährt

Bugfix release with fixes for ACME email configuration, pull request counters, actions issues and various UI improvements

v1.25.1
04.11.2025
REL
Self-hosted apps Medium bewährt

Gitea v1.25.0 introduces breaking changes to API responses and metrics, security updates, new features like 3D file preview and workflow emails, plus numerous enhancements and bug fixes

v1.25.0
29.10.2025
REL
Self-hosted apps High bewährt

Security update fixes LFS authentication bypass, symlink bypass, password leaks in logs and OAuth2 issues

v1.24.7
25.10.2025
REL
Self-hosted apps Medium Breaking

Gitea v1.25.0-rc0 Release Candidate with breaking changes in API responses and metrics, new features like 3D file preview and workflow emails

v1.25.0-rc0
25.09.2025
REL
Self-hosted apps Medium bewährt

Security update for xz library and bug fixes for compare pages, pull request redirects, API responses and webhook functionality

v1.24.6
11.09.2025
REL
Self-hosted apps Low bewährt

Bug fixes for LFS garbage collection, webhook comment counting and pull request reviews plus UI improvement for resolved comments

v1.24.5
13.08.2025
REL
Self-hosted apps Low bewährt

Bug fixes for migration inputs, file upload display, review comments, submodules and improvements to syntax highlighting and commit display

v1.24.4
04.08.2025
REL
Self-hosted apps Medium bewährt

Bugfix release with corrections for submodules, git graph, API responses, user permissions and various UI issues

v1.24.3
15.07.2025
REL
Self-hosted apps Medium bewährt

Quick bugfix release addressing Docker image push issues and Chi framework update

v1.24.2
20.06.2025
REL
Self-hosted apps Low bewährt

Maintenance update with improvements for commit status display and PR parameters plus bug fixes for package deletion, markdown rendering and API panics

v1.24.1
19.06.2025
REL
Self-hosted apps Medium Breaking

Gitea v1.24.0 introduces breaking changes to configuration handling, new features like 2FA enforcement and anonymous access to private repositories, plus performance improvements

v1.24.0
10.06.2025
REL
Self-hosted apps High bewährt

Security update for Gitea with fixes for LFS SSH upload bug and network package updates plus various bug fixes

v1.23.8
12.05.2025
REL
Self-hosted apps Medium Breaking

Gitea v1.24.0-rc0 introduces breaking configuration changes, new 2FA enforcement, enhanced repository features and performance improvements

v1.24.0-rc0
30.04.2025
REL
Self-hosted apps Medium bewährt

Security update with Go 1.23.8, new configuration option for anonymous users and various bug fixes

v1.23.7
07.04.2025
REL
Self-hosted apps High bewährt

Security update with fixes for LFS URLs, JWT/Redis packages and various bugfixes for OAuth2, Maven, markdown rendering and UI issues

v1.23.6
24.03.2025
REL
Self-hosted apps Medium bewährt

Security update with Go 1.23.7 and OAuth2/crypto libraries, performance improvements for user dashboard and various bug fixes

v1.23.5
05.03.2025
REL
Self-hosted apps High bewährt

Security update with enhancements for Actions routers, performance optimizations for pull request comments, and various bug fixes

v1.23.4
19.02.2025
REL
Self-hosted apps Medium bewährt

Security update with Golang 1.23.6 and fix for status webhook template bug

v1.23.3
06.02.2025
REL
Self-hosted apps Low Breaking

Gitea v1.23.2 fixes webhook structure issues and brings UI improvements along with numerous bugfixes

v1.23.2
05.02.2025
REL
Self-hosted apps Low bewährt

Maintenance update with UI improvements and bug fixes for repository display, API references and editor functionality

v1.23.1
10.01.2025
REL
Self-hosted apps High Breaking

Gitea v1.23.0 introduces breaking changes to SSH RSA signing, OIDC authentication and configuration options along with new features like Passkey login, Arch package registry and improved performance

v1.23.0
09.01.2025
REL
Self-hosted apps High Breaking

Gitea v1.23.0-rc0 introduces breaking changes to configuration and SSH signatures, new features like Passkey login and Arch package registry, plus security fixes

v1.23.0-rc0
17.12.2024