Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-20912

35
FAUCET Score

CVE-2026-20912 is a critical vulnerability in Gitea that allows an attacker to link attachments from private repositories to releases in public repositories due to improper validation of repository ownership. This could expose sensitive data to unauthorized users. With a CVSS score of 9.1 (CRITICAL), the vulnerability is easily exploitable over the network with no user interaction, leading to high confidentiality and integrity impacts. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion, indicating awareness and potential future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.25.4CPE matchmatch criteria
cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.41%
Probability of exploitation in next 30 days
EPSS Percentile
34.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0042 is in the 11th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/go-gitea/giteaFixed in: 1.25.4

Vendor Advisories (2)

goGHSA-4xx9-vc8v-87hvmedium

Gitea does not properly validate repository ownership when linking attachments to releases

Jan 23, 2026
redhatCVE-2026-20912Critical

gitea: Gitea: Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attachment Disclosure

Jan 22, 2026

References

access.redhat.com / security/cve/CVE-2026-20912
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-20912.json
blog.gitea.com / release-of-1.25.4
Release Notes
github.com / go-gitea/gitea/pull/36320
Issue TrackingPatch
github.com / go-gitea/gitea/pull/36355
Issue TrackingPatch
github.com / go-gitea/gitea/releases/tag/v1.25.4
Release Notes
github.com / go-gitea/gitea/security/advisories/GHSA-vfmv-f93v-37mw
Broken Link