PT-2026-4294 · Gitea+1 · Gitea+1

·

CVE-2026-20912

·

Published

2026-01-22

·

Updated

2026-07-30

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Gitea (affected versions not specified)
Description The software does not correctly check ownership of repositories when managing attachments linked to releases. This can lead to a situation where an attachment from a private repository is incorrectly associated with a release in a public repository, potentially exposing the attachment to unauthorized access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

IDOR

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-GITEA-2026-20912
CVE-2026-20912
GHSA-4XX9-VC8V-87HV
GHSA-VFMV-F93V-37MW
GO-2026-4364
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:0403-1

Affected Products

Gitea
Red Os