CVE-2025-68940

LOW3.1EPSS 0.01%

Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea

Published: 12/26/2025Modified: 1/3/2026
Also known as:GHSA-rrcw-5rjv-vj26BIT-gitea-2025-68940GO-2025-4267

Description

In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1LOW3.1CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

References (7)