CVE-2026-20912
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository c
CVSS
9.1
Crítico
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Publicado: 22 ene 2026 · Última mod.: 15 jul 2026 · CWE-284 · CWE-639 · CWE-283
0.4%EPSS · 30 días0.4%
2026-06-302026-07-19
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users.
- blog.gitea.comhttps://blog.gitea.com/release-of-1.25.4/
- github.comhttps://github.com/go-gitea/gitea/pull/36320
- github.comhttps://github.com/go-gitea/gitea/pull/36355
- github.comhttps://github.com/go-gitea/gitea/releases/tag/v1.25.4
- github.comhttps://github.com/go-gitea/gitea/security/advisories/GHSA-vfmv-f93v-37mw
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-20912
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2432219
- security.access.redhat.comhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-20912.json
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-552558.4 ALT42.8%
KEV—63Langflow Authorization Bypass Through User-Controlled Key Vulnerability12dCVE-2021-464168.1 ALT89.9%
——27Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.7dCVE-2026-503517.8 ALT84.9%
——25Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.4dCVE-2026-504237.8 ALT82.8%
——25Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.5dCVE-2026-498057.0 ALT81.6%
——24Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.4dCVE-2023-285319.8 CRÍ81.1%
——24ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.6d