PT-2025-53437 · Gitea+1 · Gitea+1

Published

2025-12-26

·

Updated

2026-02-24

·

CVE-2025-68940

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gitea versions prior to 1.22.5
Description A permission enforcement issue exists in Gitea related to branch deletion after a pull request merge. Specifically, the system does not adequately enforce branch deletion permissions in these scenarios.
Recommendations Update to Gitea version 1.22.5 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-GITEA-2025-68940
CVE-2025-68940
GHSA-RRCW-5RJV-VJ26
GO-2025-4267
SUSE-SU-2026:0037-1

Affected Products

Gitea
Red Os