CI/CD
Gitea: what changed
In the last 90 days, 39 summarized changes: 33 security advisories, 6 fixes. Stackdiff reads Gitea's own feeds (github.com) and writes two sentences per change with a link to the source; it never republishes release notes. Sources last checked .
Needs attention
Breaking changes, security advisories, end-of-life and license changes from the last 90 days, worst first.
1.26.0Securitycritical
GHSA-vhq7-fwwh-7hjf: Gitea pre-receive hook scanner errors allow branch-protection bypass
1.25.5Securitycritical
GHSA-rc56-rj3f-xggf: Gitea LFS mirror operations bypass migration HTTP transport protections
1.25.5Securitycritical
GHSA-h697-89cp-24q8: Gitea template repository generation follows unsafe filesystem paths
1.25.5Securitycritical
GHSA-922f-hfwp-p56f: Gitea repository creation accepts insufficiently validated fields
1.25.5Securitycritical
GHSA-5v69-g2m3-3hq3: Gitea OAuth2 authorization codes can be reused after expiry
1.25.5Securitycritical
GHSA-m5ch-ppfx-xv3v: Gitea OAuth2 PKCE S256 verifier bypass
1.27.1Securityhigh
GO-2026-6433: Gitea: Remote Code Execution via diffpatch Git Hook Installation in gitea.dev
1.25.5Securityhigh
GHSA-v8f2-2ghq-9whv: Gitea forwarded-proto validation allows canonical URL spoofing
1.25.5Securityhigh
GHSA-4c8f-3m6h-m56r: Gitea primary email ownership bypass allows cross-user email changes
1.25.5Securityhigh
GHSA-47rq-xp99-92mx: Gitea pull request branch permission checks allow unauthorized updates and rebases
1.25.5Securityhigh
GHSA-37w2-86g3-h4qh: Gitea organization permission APIs expose hidden membership and private organization data
1.25.5Securityhigh
GHSA-h9c5-x7g8-4q7f: Gitea git grep searches allow server resource exhaustion
Latest changes
Newest first, every type. Releases and fixes sit below anything that can hurt you in the weekly brief; here they are in order.
1.26.0Securitymedium
GO-2026-6346: Gitea pre-receive hook scanner errors allow branch-protection bypass in code.gitea.io/gitea
1.25.5Securitymedium
GO-2026-6343: Gitea tracked-time deletion is not scoped to the requested issue in code.gitea.io/gitea
1.25.5Securitymedium
GO-2026-6344: Gitea LFS mirror operations bypass migration HTTP transport protections in code.gitea.io/gitea
1.25.5Securitymedium
GO-2026-6345: Gitea forwarded-proto validation allows canonical URL spoofing in code.gitea.io/gitea
1.27.1Securityhigh
GO-2026-6433: Gitea: Remote Code Execution via diffpatch Git Hook Installation in gitea.dev
1.25.5Securitymedium
GO-2026-6347: Gitea draft releases and attachments are exposed without write permission in code.gitea.io/gitea
1.25.5Securitymedium
GO-2026-6334: Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
1.25.5Securitymedium
GO-2026-6338: Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
1.25.5Securitymedium
GO-2026-6337: Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
1.25.5Securitymedium
GO-2026-6336: Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
1.25.5Securitymedium
GO-2026-6335: Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
1.25.5Securitymedium
GO-2026-6333: Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
1.25.5Securitymedium
GO-2026-6342: Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
1.25.5Securitymedium
GO-2026-6341: Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
1.25.5Securitymedium
GO-2026-6340: Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
1.25.5Securitymedium
GO-2026-6339: Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
1.25.5Securitymedium
GHSA-7jvx-g65v-r899: Gitea release asset dumps permit path traversal through crafted names
1.25.5Securityhigh
GHSA-v8f2-2ghq-9whv: Gitea forwarded-proto validation allows canonical URL spoofing
1.26.0Securitycritical
GHSA-vhq7-fwwh-7hjf: Gitea pre-receive hook scanner errors allow branch-protection bypass
1.25.5Securitymedium
GHSA-qm72-8prh-g92x: Gitea tracked-time deletion is not scoped to the requested issue
1.25.5Securitycritical
GHSA-rc56-rj3f-xggf: Gitea LFS mirror operations bypass migration HTTP transport protections
1.25.5Securitycritical
GHSA-h697-89cp-24q8: Gitea template repository generation follows unsafe filesystem paths
1.25.5Securitymedium
GHSA-fhq3-p242-2qpf: Gitea exposes tracked time entries without repository authorization
1.25.5Securitycritical
GHSA-922f-hfwp-p56f: Gitea repository creation accepts insufficiently validated fields
1.25.5Securitycritical
GHSA-5v69-g2m3-3hq3: Gitea OAuth2 authorization codes can be reused after expiry
Where Stackdiff reads Gitea
- GitHub releases · go-gitea/gitea
- Hacker News
- OSV advisories · code.gitea.io/gitea
Only what the vendor publishes for machines. Excerpts are capped, summaries are our own two sentences, and every line links back.
Get Gitea changes in your Monday brief
Add Gitea and the rest of your stack; breaking changes and CVEs go out the moment they're seen, everything else on Monday.
Get your first brief →