Junglewise Threat Intelligence

CVE-2026-20736: Gitea improper access control in attachment deletion

CVE-2026-20736 · Severity: high · CVSS 7.5 · Published 2026-01-22

Technologies: code.gitea.io/gitea (Go), Gitea. Vendors: Go, Red Hat, Gitea.

Executive brief

Gitea, a popular self-hosted Git service, contains a security flaw in how it handles file attachments. An authorized user who previously uploaded a file to a project could potentially delete that file even after their access to the project has been revoked. This could lead to unauthorized data loss or disruption of project documentation and releases.

Technical details

A broken access control vulnerability (CWE-284) exists in Gitea's attachment deletion logic. The application fails to properly validate that a requested attachment deletion belongs to the repository context provided in the request. An attacker who previously uploaded an attachment to a repository can exploit this by losing access to that repository and then submitting a deletion request for the original attachment ID through a different repository they still control. This cross-repository unauthorized deletion is possible because the backend only checks if the user 'owned' the attachment rather than verifying the attachment's association with the current repository context. The issue is fixed in Gitea version 1.25.4.

Affected products

  • Gitea Gitea Open Source Git Server < 1.25.4
  • Red Hat OpenShift Pipelines 1

Timeline

  • 2026-01-07: patched: Initial pull request to fix the attachment check submitted.
  • 2026-01-22: advisory: Gitea 1.25.4 released with security fixes.
  • 2026-01-22: disclosed: CVE-2026-20736 published.

References

Related threats