Junglewise Threat Intelligence

CVE-2026-20904: GO-2026-4369 - Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea

CVE-2026-20904 · Severity: medium · CVSS 4 · Published 2026-02-02

Technologies: code.gitea.io/gitea (Go), github.com/go-gitea/gitea (Go). Vendors: Go.

Executive brief

Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea

Affected products

  • Go code.gitea.io/gitea
  • Go github.com/go-gitea/gitea

Related threats