PT-2026-107293 · Gitea · Gitea
CVE-2026-105267
·
Published
2026-10-06
·
Updated
2026-10-06
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gitea (affected versions not specified)
Description
The web route
POST /{owner}/{repo}/tags/delete requires only write access to the Code unit. Because this route shares its handler with release deletion and fails to verify if the target is a plain tag, a collaborator with Code write access but without Releases write access can permanently delete published releases and their associated attachments. Protected tag rules covering the release tag prevent this deletion.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Permission
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitea