CVE-2026-20736
Gitea Gitea Open Source Git Server, OpenShift Pipelines, gitea
Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a different repository they can access.
- CVSS
- 7.5
- EPSS
- 0.39% 31.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.01.23