Gitea Authorization Vulnerability in Release Deletion

Vulnerability

An authorization vulnerability has been identified in Gitea versions prior to 1.25.2, which improperly manages permissions for deleting releases. This issue could allow users to delete releases without the necessary authorization.

Impact

Exploitation of this vulnerability could lead to unauthorized deletion of release tags, potentially causing confusion or disruption in project versioning and release management.

Reproduction

The vulnerability can be reproduced by attempting to delete a release tag without the appropriate permissions. In Gitea, this can be done by a user who does not have write access to the repository. The deletion request can be made through the API or the web interface, depending on the user's access rights.

Remediation

Users are advised to upgrade to Gitea version 1.25.2, which addresses this vulnerability by implementing proper permission checks for release deletion. Instructions for upgrading can be found in the Gitea documentation.

Added: Dec 26, 2025, 2:17 AM
Updated: Dec 26, 2025, 2:17 AM

Vulnerability Rating

Custom Algorithm
spread
7.6
impact
0.6
exploitability
6.4
remediation
7.7
relevance
1.7
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.