CVE-2026-20888: Gitea
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.
Affected products
- Gitea Gitea: before 1.25.4 (fixed in 1.25.4)
Published 2026-01-22. Last modified 2026-06-17.