Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
02 / AFFECTED SOFTWARE
Affected packages
43 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.
Gitea does not properly validate repository ownership when deleting Git LFS locks in code.gitea.io/gitea
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.
05 / REFERENCES
Further evidence
- https://access.redhat.com/security/cve/CVE-2026-20897
- https://blog.gitea.com/release-of-1.25.4/
- https://bugzilla.redhat.com/show_bug.cgi?id=2432204
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/20xxx/CVE-2026-20897.json
- https://github.com/go-gitea/gitea/pull/36344
- https://github.com/go-gitea/gitea/pull/36349
- https://github.com/go-gitea/gitea/releases/tag/v1.25.4
- https://github.com/go-gitea/gitea/security/advisories/GHSA-rrq5-r9h5-pc7c
- https://nvd.nist.gov/vuln/detail/CVE-2026-20897
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-20897.json
- https://blog.gitea.com/release-of-1.25.4
- https://github.com/advisories/GHSA-393c-qgvj-3xph
- https://github.com/go-gitea/gitea/commit/da036f3f35ca830b22cf4480912ed261303b798f
- https://github.com/go-gitea/gitea