Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
02 / AFFECTED SOFTWARE
Affected packages
43 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a different repository they can access.
Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a different repository they can access.
Gitea has improper access control for uploaded attachments in code.gitea.io/gitea
Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a different repository they can access.
05 / REFERENCES
Further evidence
- https://access.redhat.com/security/cve/CVE-2026-20736
- https://blog.gitea.com/release-of-1.25.4/
- https://bugzilla.redhat.com/show_bug.cgi?id=2432205
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/20xxx/CVE-2026-20736.json
- https://github.com/go-gitea/gitea/pull/36320
- https://github.com/go-gitea/gitea/releases/tag/v1.25.4
- https://github.com/go-gitea/gitea/security/advisories/GHSA-jr6h-pwwp-c8g6
- https://nvd.nist.gov/vuln/detail/CVE-2026-20736
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-20736.json
- https://blog.gitea.com/release-of-1.25.4
- https://github.com/advisories/GHSA-hgr3-x44x-33hx
- https://github.com/go-gitea/gitea/commit/fbea2c68e8df11cfa94e8ead913b79946780ed30
- https://github.com/go-gitea/gitea