Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xfq3-qj7j-4565 | Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources |
Fri, 02 Jan 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:* |
Sat, 27 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | gitea: Gitea: Unauthorized access to private resources via public-scoped API tokens | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 26 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Dec 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources. | |
| First Time appeared |
Gitea
Gitea gitea |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitea
Gitea gitea |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-26T19:31:33.303Z
Reserved: 2025-12-26T02:31:58.775Z
Link: CVE-2025-68941
Updated: 2025-12-26T19:31:30.258Z
Status : Analyzed
Published: 2025-12-26T03:15:50.967
Modified: 2026-01-02T19:33:13.143
Link: CVE-2025-68941
OpenCVE Enrichment
No data.
Github GHSA