Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f85h-c7m6-cfpm | Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries |
Wed, 31 Dec 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:* |
Sat, 27 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | gitea: Gitea: Access control bypass in package registries | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 26 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Dec 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries. | |
| First Time appeared |
Gitea
Gitea gitea |
|
| Weaknesses | CWE-441 | |
| CPEs | cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitea
Gitea gitea |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-26T19:28:23.900Z
Reserved: 2025-12-26T03:37:28.412Z
Link: CVE-2025-68944
Updated: 2025-12-26T19:28:21.087Z
Status : Analyzed
Published: 2025-12-26T04:15:41.357
Modified: 2025-12-31T22:30:32.697
Link: CVE-2025-68944
OpenCVE Enrichment
No data.
Github GHSA