CVE-2026-20888: Gitea

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.

Affected products

  • Gitea Gitea: before 1.25.4 (fixed in 1.25.4)

Published 2026-01-22. Last modified 2026-06-17.