216.73.217.55

CVE-2026-20904

· Published 22/01/2026 22:16 · Modified 23/01/2026 22:16

Labels: CVE-2026-20904 2026-01-2288ee5874-cf24-4952-aea0-31affedb7ff2CVE-2026-20904CWE-284

Essential information

Published
22/01/2026 22:16
Modified
23/01/2026 22:16
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CVSS metrics

Description

Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
88ee5874-cf24-4952-aea0-31affedb7ff2
NVD
View on NVD

Affected products (CPE)

ProductCPE
gitea / gitea cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:*

References