VDB
GO-2025-4264
GO-2025-4264
PUBLISHED
Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| code.gitea.io | gitea | 0, 0 |
Timeline
- Dec 30, 2025 CVE Published
- Mar 3, 2026 CVE Updated
- May 1, 2026 Security Advisory