CVE-2025-68944
5.0MEDIUMGitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.
Published: 12/26/2025Updated: 12/31/2025
Description
Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.
AI AnalysisPowered by AI
Affected Products
giteagitea
References
- https://blog.gitea.com/release-of-1.22.2/Release Notes
- https://github.com/go-gitea/gitea/pull/31967Issue Tracking
- https://github.com/go-gitea/gitea/releases/tag/v1.22.2Release Notes