Junglewise Threat Intelligence

CVE-2026-20888: GO-2026-4366 - Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea

CVE-2026-20888 · Severity: medium · CVSS 4 · Published 2026-02-02

Technologies: code.gitea.io/gitea (Go), github.com/go-gitea/gitea (Go). Vendors: Go.

Executive brief

Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea

Affected products

  • Go code.gitea.io/gitea
  • Go github.com/go-gitea/gitea

Related threats