CVE-2026-58441 – Gitea Open Source Git Server

CVSS 6.3 MODERATE Zero Day – Immediate Deployment

“Widespread access-control flaws can expose private repositories, elevate privileges, and break trust boundaries across Gitea.”

Gitea is affected by 48 vulnerabilities spanning privilege escalation, authorization and token-scope bypasses, SSRF, private repository and identity disclosure, denial of service, and repository security-control weaknesses. Critical vulnerabilities include CVE-2026-56654 with a CVSS score of 9.8, CVE-2026-56443 with a CVSS score of 9.6, and CVE-2026-55982, CVE-2026-58433, CVE-2026-58443, CVE-2026-58508, and CVE-2026-56750 with CVSS scores of 9.1. All are Critical severity.

High-severity vulnerabilities range from CVSS 7.1 to 8.5 and include private-resource authorization bypasses, SSRF, repository information exposure, TLS validation weaknesses, branch protection bypass, and unauthorized repository manipulation. Additional Medium and Low vulnerabilities affect token enforcement, package processing, webhooks, repository migration, information disclosure, and denial-of-service protections. Public proof-of-concept information is available for many vulnerabilities in this group.

CVE List:

CVE-2026-23603, CVE-2026-24059, CVE-2026-24791, CVE-2026-42931, CVE-2026-50105, CVE-2026-54481, CVE-2026-55982, CVE-2026-55984, CVE-2026-55986, CVE-2026-55987, CVE-2026-25714, CVE-2026-56443, CVE-2026-56654, CVE-2026-56657, CVE-2026-56750, CVE-2026-56755, CVE-2026-57886, CVE-2026-57894, CVE-2026-57897, CVE-2026-58314, CVE-2026-58416, CVE-2026-58417, CVE-2026-58420, CVE-2026-58425, CVE-2026-58427, CVE-2026-58428, CVE-2026-58429, CVE-2026-58431, CVE-2026-58432, CVE-2026-58433, CVE-2026-58434, CVE-2026-58435, CVE-2026-58436, CVE-2026-58437, CVE-2026-58438, CVE-2026-58439, CVE-2026-58440, CVE-2026-58441, CVE-2026-58442, CVE-2026-58443, CVE-2026-58444, CVE-2026-58445, CVE-2026-58507, CVE-2026-58508, CVE-2026-58510, CVE-2026-58511, CVE-2026-59763, CVE-2026-59765

Key Details

Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-918
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.