CVE-2025-68940

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/12/2025
Last modified:
02/01/2026

Description

In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:* 1.22.5 (excluding)