PT-2026-107293 · Gitea · Gitea

CVE-2026-105267

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gitea (affected versions not specified)
Description The web route POST /{owner}/{repo}/tags/delete requires only write access to the Code unit. Because this route shares its handler with release deletion and fails to verify if the target is a plain tag, a collaborator with Code write access but without Releases write access can permanently delete published releases and their associated attachments. Protected tag rules covering the release tag prevent this deletion.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105267
GHSA-VVQW-MJQ8-X248

Affected Products

Gitea