Feed/CVE-2026-20904
CVE-2026-20904MEDIUMCVSS 6.5

CVE-2026-20904

Published Jan 22, 2026·Updated Jun 17, 2026

NVD Description

Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free