UNKNOWN Go
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
GHSA-9cgq-wp42-4rpq · BIT-gitea-2026-20888 · CVE-2026-20888 · GHSA-ccq9-c5hv-cf64 · GO-2026-4366
Published · Modified
Description
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-20888
- WEB https://github.com/go-gitea/gitea/pull/36341
- WEB https://github.com/go-gitea/gitea/pull/36356
- WEB https://blog.gitea.com/release-of-1.25.4
- PACKAGE https://github.com/go-gitea/gitea
- WEB https://github.com/go-gitea/gitea/releases/tag/v1.25.4
Ready to move
Start Securing
Free, no credit card | First findings in minutes