Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hgr3-x44x-33hx | Gitea has improper access control for uploaded attachments |
Thu, 29 Jan 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:* |
Tue, 27 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 23 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 23 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitea
Gitea gitea |
|
| Vendors & Products |
Gitea
Gitea gitea |
Thu, 22 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a different repository they can access. | |
| Title | Gitea Web Attachment Deletion: Cross-Repository Unauthorized Deletion via Missing Repo Ownership Check | |
| Weaknesses | CWE-284 | |
| References |
|
Status: PUBLISHED
Assigner: Gitea
Published:
Updated: 2026-01-23T21:54:48.862Z
Reserved: 2026-01-08T23:02:37.558Z
Link: CVE-2026-20736
Updated: 2026-01-23T21:13:18.343Z
Status : Analyzed
Published: 2026-01-22T22:16:17.207
Modified: 2026-01-29T21:46:59.497
Link: CVE-2026-20736
OpenCVE Enrichment
Updated: 2026-04-18T03:45:21Z
Github GHSA