CVE-2026-105267 PUBLISHED

Gitea tag delete route deletes releases without release permission

Assigner: Gitea
Reserved: 04.10.2026 Published: 06.10.2026 Updated: 06.10.2026

The Gitea web route for deleting tags (POST /{owner}/{repo}/tags/delete) requires only write access to the Code unit, but shares its handler with release deletion and did not check that the target was a plain tag. A collaborator with Code write access and without Releases write access could permanently delete published releases of that repository, including their attachments. Protected tag rules covering the release tag still blocked the deletion.

Product Status

Vendor Gitea
Product Gitea
Versions Default: unaffected
  • affected from 0 to 28.0.0 (incl.)

Credits

  • https://github.com/N0K0 reporter
  • https://github.com/silverwind remediation developer
  • https://github.com/bircni remediation developer

References

Problem Types

  • CWE-732: Incorrect Permission Assignment for Critical Resource CWE
  • CWE-863: Incorrect Authorization CWE