PatchSiren cyber security CVE debrief
CVE-2026-105267 Gitea CVE debrief
A collaborator with Code write access could delete published releases of a repository without Releases write access due to a flaw in Gitea's tag deletion route. This vulnerability allows unintended release deletion, potentially leading to data loss and increased risk for Gitea instances with untrusted collaborators. Gitea instance administrators should assess exposure and apply patches promptly to mitigate potential impacts. Collaborators with Code write access can permanently delete published releases, including their attachments, without having Releases write access.
- Vendor
- Gitea
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-06
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-06
- Advisory updated
- 2026-10-07
Who should care
Gitea instance administrators and collaborators with Code write access should assess exposure and apply patches promptly. Defenders should prioritize verifying exposure and applying patches for Gitea instances with untrusted collaborators to mitigate potential impacts. Gitea instance administrators should review compensating controls and monitor for suspicious activity.
Why it matters
Defenders should care about this vulnerability as it allows collaborators with Code write access to delete published releases without Releases write access, potentially leading to data loss and increased risk for Gitea instances with untrusted collaborators.
- Unintended release deletion by collaborators
- Potential data loss due to release attachment deletion
- Increased risk for Gitea instances with untrusted collaborators
- Verification priority for Gitea instance administrators
Technical summary
The Gitea web route for deleting tags requires only write access to the Code unit but did not check if the target was a plain tag. This flaw allows collaborators with Code write access to delete published releases without Releases write access, potentially leading to data loss. The vulnerability highlights the importance of proper access controls and validation in Gitea's tag deletion process. Defenders should prioritize verifying exposure and applying patches for Gitea instances with untrusted collaborators to mitigate potential impacts.
Defensive priority
Defenders should prioritize verifying exposure and applying patches for Gitea instances with untrusted collaborators.
Recommended defensive actions
- Verify Gitea instance exposure and apply patches
- Restrict Code write access to trusted collaborators
- Monitor for suspicious release deletion activity
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
- Plan vendor-supported updates through normal change control
Evidence notes
The CVE record and source item provide details on the vulnerability and affected versions. The Gitea web route for deleting tags requires only write access to the Code unit but did not check if the target was a plain tag, allowing collaborators with Code write access to delete published releases without Releases write access. There are no known exploits, but defenders should verify exposure and apply patches. Official CVE Program record and NIST NVD detail page provide additional information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105267 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105267
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105267 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105267
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Gitea tag delete route deletes releases without release permission
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105267.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/security/advisories/GHSA-vvqw-mjq8-x248
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/pull/39501
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/pull/39507
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://blog.gitea.com/release-of-28.1.0/
Supplemental source - release-notes
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/releases/tag/v28.1.0
Supplemental source - release-notes
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.