Advisories for Golang/Github.com/Go-Gitea/Gitea package

2026

Gitea: Open Redirect via redirect_to

Phishing: Attackers can use trusted domain links to redirect victims to credential-harvesting pages OAuth/SSO Token Theft: In authentication flows, authorization codes or tokens may leak via redirect Referer Leakage: Sensitive URL parameters may be exposed to attacker domains via the Referer header Cache Poisoning: In deployments with shared caches, malicious redirects may be cached and served to other users

2023
2022
2021
2020
2019

Improper Access Control

Gitea contains a Incorrect Access Control vulnerability in Delete/Edit file functionallity that can result in the attacker deleting files outside the repository he/she has access to. This attack appears to be exploitable via the attacker must get write access to any repository including self-created ones.

2018