PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105267 Gitea CVE debrief

A collaborator with Code write access could delete published releases of a repository without Releases write access due to a flaw in Gitea's tag deletion route. This vulnerability allows unintended release deletion, potentially leading to data loss and increased risk for Gitea instances with untrusted collaborators. Gitea instance administrators should assess exposure and apply patches promptly to mitigate potential impacts. Collaborators with Code write access can permanently delete published releases, including their attachments, without having Releases write access.

Vendor
Gitea
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-06
Original CVE updated
2026-10-07
Advisory published
2026-10-06
Advisory updated
2026-10-07

Who should care

Gitea instance administrators and collaborators with Code write access should assess exposure and apply patches promptly. Defenders should prioritize verifying exposure and applying patches for Gitea instances with untrusted collaborators to mitigate potential impacts. Gitea instance administrators should review compensating controls and monitor for suspicious activity.

Why it matters

Defenders should care about this vulnerability as it allows collaborators with Code write access to delete published releases without Releases write access, potentially leading to data loss and increased risk for Gitea instances with untrusted collaborators.

  • Unintended release deletion by collaborators
  • Potential data loss due to release attachment deletion
  • Increased risk for Gitea instances with untrusted collaborators
  • Verification priority for Gitea instance administrators

Technical summary

The Gitea web route for deleting tags requires only write access to the Code unit but did not check if the target was a plain tag. This flaw allows collaborators with Code write access to delete published releases without Releases write access, potentially leading to data loss. The vulnerability highlights the importance of proper access controls and validation in Gitea's tag deletion process. Defenders should prioritize verifying exposure and applying patches for Gitea instances with untrusted collaborators to mitigate potential impacts.

Defensive priority

Defenders should prioritize verifying exposure and applying patches for Gitea instances with untrusted collaborators.

Recommended defensive actions

  • Verify Gitea instance exposure and apply patches
  • Restrict Code write access to trusted collaborators
  • Monitor for suspicious release deletion activity
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets
  • Plan vendor-supported updates through normal change control

Evidence notes

The CVE record and source item provide details on the vulnerability and affected versions. The Gitea web route for deleting tags requires only write access to the Code unit but did not check if the target was a plain tag, allowing collaborators with Code write access to delete published releases without Releases write access. There are no known exploits, but defenders should verify exposure and apply patches. Official CVE Program record and NIST NVD detail page provide additional information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105267 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105267

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105267 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105267

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Gitea tag delete route deletes releases without release permission

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105267.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/security/advisories/GHSA-vvqw-mjq8-x248

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/pull/39501

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/pull/39507

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://blog.gitea.com/release-of-28.1.0/

    Supplemental source - release-notes

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/releases/tag/v28.1.0

    Supplemental source - release-notes

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.