CVE-2020-13246: Gitea

High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.

An issue was discovered in Gitea through 1.11.5. An attacker can trigger a deadlock by initiating a transfer of a repository's ownership from one organization to another.

Affected products

  • Gitea Gitea: up to and including 1.11.5

Published 2020-05-20. Last modified 2026-06-17.