Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
02 / AFFECTED SOFTWARE
Affected packages
43 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.
05 / REFERENCES
Further evidence
- https://blog.gitea.com/release-of-1.25.4
- https://github.com/advisories/GHSA-qqgv-v353-cv8p
- https://github.com/go-gitea/gitea/commit/ed5720af2ac94d74f822721c05b42b6148ff9c22
- https://github.com/go-gitea/gitea/pull/36346
- https://github.com/go-gitea/gitea/pull/36361
- https://github.com/go-gitea/gitea/releases/tag/v1.25.4
- https://nvd.nist.gov/vuln/detail/CVE-2026-20904
- https://github.com/go-gitea/gitea
- https://blog.gitea.com/release-of-1.25.4/
- https://github.com/go-gitea/gitea/security/advisories/GHSA-jrpc-w85r-hgqx
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/20xxx/CVE-2026-20904.json