GO-2026-6027: Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration in gitea.dev
GO-2026-6028: Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) in gitea.dev
GO-2026-6032: Gitea: Local File Inclusion via file:// URI in Migration Restore in gitea.dev
GO-2026-6033: Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content in gitea.dev
GO-2026-6034: Gitea: Privilege Escalation via Access Token Scope Escalation in API in gitea.dev
GO-2026-6035: Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content in gitea.dev
GO-2026-6036: Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) in gitea.dev
GO-2026-6037: Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload in gitea.dev
GO-2026-6039: Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev
GO-2026-6040: Gitea: Webhook Authorization Header Returned in Plaintext via API in gitea.dev
GO-2026-6042: Gitea SSH Key Parser Denial of Service in gitea.dev
GO-2026-6045: Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository
+ Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev
GO-2026-6047: Gitea: Repository Visibility Manipulation via Git Push Options in gitea.dev
GO-2026-6048: Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override in gitea.dev
GO-2026-6049: Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads in gitea.dev
GO-2026-6050: Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents in gitea.dev
GO-2026-6052: Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) in gitea.dev
GO-2026-6053: Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev
GO-2026-6054: Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs in gitea.dev
GO-2026-6055: Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests in gitea.dev
GO-2026-6058: Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass in gitea.dev
GO-2026-6059: Gitea: Public-only API token restriction is not enforced on team API routes in gitea.dev
GO-2026-6062: Gitea: Private Repository Metadata Remains Accessible After Access Revocation in gitea.dev
GO-2026-6063: Gitea: REST API exposes organization membership of private organizations to public in gitea.dev
GO-2026-6064: Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service in gitea.dev
GO-2026-6065: Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes in gitea.dev
GO-2026-6066: Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint in gitea.dev
GO-2026-6067: Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API in gitea.dev
GO-2026-6068: Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 in gitea.dev
GO-2026-6069: Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private in gitea.dev
GO-2026-6070: Gitea: draft release attachment disclosure via missing web authorization in gitea.dev
GO-2026-6071: Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev
GO-2026-6072: Gitea Remember-Me Token Theft Not Invalidating Attacker Session in gitea.dev
GO-2026-6073: Gitea LFS Deploy-Key Privilege Escalation in gitea.dev
GO-2026-6078: Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) in gitea.dev
GO-2026-6079: Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev
GO-2026-6082: Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint in gitea.dev
GO-2026-6083: Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim in gitea.dev
GO-2026-6084: Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL in gitea.dev
GO-2026-6085: Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access in gitea.dev
GO-2026-6086: Gitea: Public-only repository tokens can update private PR head branches in gitea.dev