Access Control Issues in Gitea Affecting Tag and Release Management
CVE-2026-105267

Currently unrated

Key Information:

Vendor

Gitea

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105267?

A vulnerability in Gitea allows users with write access to repository code to delete published releases, including attachments, without having the appropriate release management permission. This occurs through the shared handler for deleting tags and releases, which fails to adequately verify the type of tag being deleted. As a result, even users with restricted access can permanently erase important repository artifacts. Protected tag rules do not prevent the deletion of release tags, further compromising repository security and integrity.

Affected Version(s)

Gitea 0 <= 28.0.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

https://github.com/N0K0
https://github.com/silverwind
https://github.com/bircni
.