Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitea
Gitea gitea |
|
| Vendors & Products |
Gitea
Gitea gitea |
Tue, 06 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Gitea web route for deleting tags (`POST /{owner}/{repo}/tags/delete`) requires only write access to the Code unit, but shares its handler with release deletion and did not check that the target was a plain tag. A collaborator with Code write access and without Releases write access could permanently delete published releases of that repository, including their attachments. Protected tag rules covering the release tag still blocked the deletion. | |
| Title | Gitea tag delete route deletes releases without release permission | |
| Weaknesses | CWE-732 CWE-863 |
|
| References |
|
Status: PUBLISHED
Assigner: Gitea
Published:
Updated: 2026-10-07T20:02:51.066Z
Reserved: 2026-10-04T22:02:04.888Z
Link: CVE-2026-105267
No data.
Status : Awaiting Analysis
Published: 2026-10-06T22:17:02.253
Modified: 2026-10-07T13:45:36.947
Link: CVE-2026-105267
No data.
OpenCVE Enrichment
Updated: 2026-10-07T05:00:11Z