UNKNOWN Go
Gitea does not properly validate repository ownership when linking attachments to releases
GHSA-4xx9-vc8v-87hv · BIT-gitea-2026-20912 · CVE-2026-20912 · GHSA-vfmv-f93v-37mw · GO-2026-4364
Published · Modified
Description
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-20912
- WEB https://github.com/go-gitea/gitea/pull/36320
- WEB https://github.com/go-gitea/gitea/pull/36355
- WEB https://github.com/go-gitea/gitea/commit/fbea2c68e8df11cfa94e8ead913b79946780ed30
- WEB https://blog.gitea.com/release-of-1.25.4
- PACKAGE https://github.com/go-gitea/gitea
- WEB https://github.com/go-gitea/gitea/releases/tag/v1.25.4
Ready to move
Start Securing
Free, no credit card | First findings in minutes