CVE-2025-68940Incorrect Authorization in Gitea

Severity
5.3MEDIUMNVD
EPSS
0.0%
top 97.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 26
Latest updateDec 30

Description

In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDgitea/gitea< 1.22.5
Gocode.gitea.io/gitea< 1.22.5

Patches

🔴Vulnerability Details

3
OSV
Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea2025-12-30
OSV
Gitea doesn't adequately enforce branch deletion permissions after merging a pull request.2025-12-26
GHSA
Gitea doesn't adequately enforce branch deletion permissions after merging a pull request.2025-12-26

📋Vendor Advisories

1
Red Hat
gitea: Gitea: Unauthorized branch deletion due to inadequate permission enforcement2025-12-26

🕵️Threat Intelligence

1
Wiz
CVE-2025-68940 Impact, Exploitability, and Mitigation Steps | Wiz