UNKNOWN Go
Gitea has improper access control for uploaded attachments
GHSA-hgr3-x44x-33hx · BIT-gitea-2026-20736 · CVE-2026-20736 · GHSA-jr6h-pwwp-c8g6 · GO-2026-4367
Published · Modified
Description
Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a different repository they can access.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-20736
- WEB https://github.com/go-gitea/gitea/pull/36320
- WEB https://github.com/go-gitea/gitea/commit/fbea2c68e8df11cfa94e8ead913b79946780ed30
- WEB https://blog.gitea.com/release-of-1.25.4
- PACKAGE https://github.com/go-gitea/gitea
- WEB https://github.com/go-gitea/gitea/releases/tag/v1.25.4
Ready to move
Start Securing
Free, no credit card | First findings in minutes