CVE-2026-20897
Gitea Gitea Open Source Git Server, OpenShift Pipelines, gitea
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.
- CVSS
- 9.1
- EPSS
- 0.41% 34.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.01.23