Gitea: Three Critical Security Vulnerabilities (CVE-2026-58426, -20896, -22874)


This text was generated using artificial intelligence (AI).Update July 6, 2026: In addition to CVE-2026-58426, two other critical vulnerabilities in Gitea have been disclosed. CVE-2026-20896 (CVSS 9.8) allows for complete account takeover without a password in Docker deployments with reverse proxy authentication enabled. CVE-2026-22874 (CVSS 9.6) allows authenticated users to perform server-side request forgery against internal network resources and cloud metadata endpoints. See below for details.

On the widely used, self-hosted Git platform Gitea Several critical security vulnerabilities were disclosed. The vulnerability CVE-2026-58426 with a CVSS score of 9.6 (Critical) affects the Gitea Actions feature and allows authenticated attackers with low privileges to bypass security boundaries between different projects in order to access sensitive build artifacts and manipulate their upload status. The second vulnerability CVE-2026-20896 with a CVSS score of 9.8 (Critical) affects Docker deployments and, under certain configuration conditions, allows an attacker to completely take over any user account. The third vulnerability CVE-2026-22874 with a CVSS score of 9.6 (Critical) Allows authenticated users with webhook or migration privileges to perform a non-blind server-side request forgery on internal network resources. Security updates to address all issues are available.