CVE-2026-20912
Gitea Gitea Open Source Git Server, OpenShift Pipelines, gitea
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users.
- CVSS
- 9.1
- EPSS
- 0.41% 34.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.01.23