CVE-2025-68944: Medium severity gitea vulnerability
Published Dec 26, 2025
·Updated
Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.
Affected Software
3 affected componentsFixes available
gitea<1.22.2
go/code.gitea.io/gitea<1.22.2
1.22.2
Gitea Gitea<1.22.2
Event History
Dec 26, 2025
CVE Published
via MITRE·03:37 AM
Data Sourced
via MITRE·03:37 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:30 AM
Data Sourced
via GitHub·06:30 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-68944?
The severity of CVE-2025-68944 is classified as medium due to the potential misuse of access control tokens in Gitea.
2
How do I fix CVE-2025-68944?
To fix CVE-2025-68944, upgrade Gitea to version 1.22.2 or later.
3
What versions of Gitea are affected by CVE-2025-68944?
CVE-2025-68944 affects Gitea versions prior to 1.22.2.
4
What does CVE-2025-68944 vulnerability affect?
CVE-2025-68944 affects the token scope propagation for access control within Gitea's package registries.
5
Where can I find more information about CVE-2025-68944?
More information about CVE-2025-68944 can be found in the Gitea release notes and relevant pull requests.