Loading
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users.
Use CWE-284, Gitea vendor hub and Gitea product page to widen CVE-2026-20912 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-20897, CVE-2026-20750 and CVE-2026-20736 for nearby disclosures in the same product family.