GO · JULY 2026 · EARLY WARNING

Gitea Path Resolution Vulnerability: Assess Your Exposure Now

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
code.gitea.io/gitea (go)
Affected versions
< 1.27.0 or < 1.27.0 or < 1.26.3 or < 1.27.0 or < 1.8.0 or < 1.26.2 or >= 1.1.0, < 1.12.6 or < 1.25.0 or < 1.26.3 or < 1.27.0 or < 1.26.4 or < 1.22.1 or < 1.16.5 or < 1.27.0 or < 1.7.1 or < 1.26.3 or < 1.27.0 or < 1.27.0 or < 1.27.0 or < 1.27.0 or < 1.26.3 or < 1.27.0 or >= 1.23.0, < 1.26.3 or < 1.21.2 or < 1.27.0 or < 1.26.2 or < 1.22.2 or < 1.25.4 or < 1.17.2 or < 1.27.0 or < 1.26.2 or < 1.27.0 or >= 1.25.0, < 1.26.0 or < 1.27.0 or < 1.26.2 or < 1.26.2 or < 1.19.4 or < 1.25.2 or < 1.27.0 or < 1.26.2 or < 1.26.3 or < 1.22.2 or < 1.16.0-rc1 or < 1.16.9 or < 1.26.0 or < 1.27.0 or < 1.27.0 or < 1.27.0 or < 1.16.4 or < 1.13.4 or < 1.26.4 or >= 1.5.0, < 1.26.3 or < 1.27.0 or < 1.13.6 or < 1.5.2 or < 1.5.0 or >= 1.22.0, < 1.26.2 or < 1.25.4 or < 1.20.1 or >= 1.7.2, < 1.7.4 or < 1.27.0 or < 1.6.3 or < 1.21.8 or < 1.16.4 or < 1.27.0 or < 1.27.0 or < 1.26.2 or < 1.27.0 or < 1.16.7 or < 1.25.2 or < 1.6.0 or < 1.27.0 or < 1.16.9 or < 1.27.0 or < 1.27.0 or < 1.27.0 or < 1.27.0 or < 1.27.0 or < 1.26.0 or < 1.26.4 or < 1.22.5 or < 1.26.3 or < 1.26.4 or < 1.27.0 or < 1.27.0 or < 1.27.0 or < 1.26.3 or >= 1.22.3, < 1.26.2 or < 1.27.0 or < 1.27.0 or < 1.22.3 or < 1.27.0 or < 1.27.0 or < 1.11.2 or < 1.5.0 or < 1.13.6 or < 1.16.4 or < 1.16.7 or < 1.16.4 or < 1.16.9 or < 1.12.0 or < 1.13.4 or < 1.5.2 or < 1.6.0 or < 1.17.3 or < 1.19.4 or < 1.7.1 or < 1.16.0-rc1 or < 1.17.2 or < 1.16.5 or >= 1.9.0, < 1.13.2 or < 1.16.9 or < 1.22.1 or < 1.25.2 or < 1.21.2 or < 1.22.2 or < 1.22.2 or < 1.20.1 or < 1.21.8 or < 1.22.5 or < 1.22.3 or < 1.25.2 or < 1.25.4 or < 1.25.4 or < 1.25.4 or < 1.25.4 or < 1.25.4 or < 1.25.4 or < 1.25.4 or < 1.25.4 or < 1.25.4 or < 1.26.2 or < 1.25.0 or < 1.26.2 or >= 1.25.0, < 1.26.0 or < 1.26.2 or < 1.26.2 or < 1.26.2 or < 1.26.0 or < 1.26.0 or < 1.26.2 or >= 1.22.3, < 1.26.2 or < 1.26.2 or < 1.26.3 or < 1.26.3 or < 1.26.3 or < 1.26.4 or < 1.26.3 or < 1.26.3 or >= 1.23.0, < 1.26.3 or < 1.26.3 or < 1.26.4 or >= 1.5.0, < 1.26.3 or >= 1.22.0, < 1.26.2 or < 1.26.0 or < 1.26.4 or < 1.26.3 or < 1.26.4 or < 1.26.3
Patched version
1.25.5
GHSA-H697-89CP-24Q8

Gitea versions before 1.25.5 reportedly mishandle path resolution during template repository generation, potentially allowing unauthorized read or write access.

What happened

Gitea versions before 1.25.5 appear to have a vulnerability in the way they handle path resolution during template repository generation. This mishandle could allow an attacker to read or write through symlinked or otherwise non-regular paths. The vulnerability is under investigation and has not been exploited in the wild as of the latest reports. Users of affected versions should take immediate action to assess their exposure and apply the recommended upgrade.

The vulnerability affects various versions of the code.gitea.io/gitea package. The specific versions impacted are detailed in the affected components section. It is crucial for users to check their current version against this list to determine if they are vulnerable.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If code.gitea.io/gitea is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using a version of Gitea before 1.25.5, you may be affected. Check the affected components list for specific version details.

What should I do right now?

Upgrade to Gitea version 1.25.5 or later immediately. Check your current version against the affected components list to confirm your exposure.

Is there an official patch available?

Yes, Gitea version 1.25.5 is the patched version. Upgrade to this version or later to address the vulnerability.

Where can I find more information about this vulnerability?

Consult the primary sources listed in the incident data for the most accurate and up-to-date information.

Sources

Join the 0Day waitlist →

← Back to all threats