Junglewise Threat Intelligence

CVE-2026-25714: Gitea missing authorization for public-only tokens in API

CVE-2026-25714 · Severity: medium · CVSS 4.3 · Published 2026-07-03

Technologies: code.gitea.io/gitea (Go), Gitea. Vendors: Go, Gitea.

Executive brief

Gitea, a popular self-hosted Git service, contains a security flaw where certain access tokens intended only for public data could still access private information. Specifically, the system failed to consistently block these restricted tokens when they were used to query user organizations and repository details. This could allow a user with a limited-access token to view private organizational data or repository metadata they should not be able to see.

Technical details

This vulnerability is a missing authorization check (CWE-862) resulting from an incomplete fix for a previous security issue. Gitea's API did not consistently enforce 'public-only' token restrictions across all endpoints, specifically within the user organization API and certain repository lookup functions. An attacker with a valid 'public-only' scoped token could bypass intended visibility boundaries to retrieve private resources through list/search endpoints or ID-based lookups. The fix, introduced in version 1.26.2, unifies token filtering by applying 'ApplyPublicOnly' helpers to search/list option structs and hardening repository access checks in the API context.

Affected products

  • Gitea Gitea Open Source Git Server <= 1.26.1

Timeline

  • 2026-05-20: patched: Gitea version 1.26.2 released with the fix.
  • 2026-07-03: advisory: CVE-2026-25714 published.

References

Related threats