MEDIUM 5.3 Go
Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists
GHSA-pc73-rj2c-wvf9 · BIT-gitea-2025-69413 · CVE-2025-69413 · GO-2026-4274
Published · Modified
Description
In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-69413
- WEB https://github.com/go-gitea/gitea/issues/35984
- WEB https://github.com/go-gitea/gitea/pull/36002
- WEB https://blog.gitea.com/release-of-1.25.2
- PACKAGE https://github.com/go-gitea/gitea
- WEB https://github.com/go-gitea/gitea/releases/tag/v1.25.2
Ready to move
Start Securing
Free, no credit card | First findings in minutes