CVE-2025-68938
MEDIUM WAF: Low
CVSS 5.3
Published: 2025-12-26
CWE-863
Gitea before 1.25.2 mishandles authorization for deletion of releases.
WAF Coverage Analysis
Incorrect Authorization
Low WAF Coverage
OWASP: A01:2021 Broken Access Control
Affected Software
| Vendor | Product | Version |
|---|---|---|
| gitea | gitea | up to 1.25.2 |
References
- blog.gitea.com (Release Notes)
- github.com (Patch)
- github.com (Release Notes)