CVE-2026-20897
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2026-20897, https://github.com/go-gitea/gitea/pull/36344, https://github.com/go-gitea/gitea/pull/36349, https://github.com/go-gitea/gitea/commit/da036f3f35ca830b22cf4480912ed261303b798f, https://blog.gitea.com/release-of-1.25.4, https://github.com/go-gitea/gitea, https://github.com/go-gitea/gitea/releases/tag/v1.25.4
