Medium severity5.3NVD Advisory· Published Jul 3, 2026· Updated Jul 7, 2026
CVE-2026-25782
CVE-2026-25782
Description
Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
code.gitea.io/giteaGo | < 1.25.5 | 1.25.5 |
Affected products
1Patches
Vulnerability mechanics
References
9- github.com/advisories/GHSA-qm72-8prh-g92xghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-25782ghsaADVISORY
- blog.gitea.com/release-of-1.25.5ghsaWEB
- github.com/go-gitea/gitea/commit/5ad87616c9c654fc44c611ccfd4e496257c8f96bghsaWEB
- github.com/go-gitea/gitea/commit/8051056075719b7629eef44689b5a61d5ff080a9ghsaWEB
- github.com/go-gitea/gitea/pull/36664nvdWEB
- github.com/go-gitea/gitea/pull/36689nvdWEB
- github.com/go-gitea/gitea/releases/tag/v1.25.5nvdWEB
- blog.gitea.com/release-of-1.25.5/nvd
News mentions
0No linked articles in our index yet.