CVE-2026-105267: Gitea tag delete route deletes releases without release permission
The Gitea web route for deleting tags (POST /{owner}/{repo}/tags/delete) requires only write access to the Code unit, but shares its handler with release deletion and did not check that the target was a plain tag. A collaborator with Code write access and without Releases write access could permanently delete published releases of that repository, including their attachments. Protected tag rules covering the release tag still blocked the deletion.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure protected tag rules covering the repository's release tag to block tag deletion.
Gitea Protected tag rules = Cover the release tag
Event History
Frequently Asked Questions
Who can exploit this issue?
A collaborator who has write access to the repository's Code unit but does not have write access to Releases can exploit it. The collaborator must be able to use the web tag-deletion route for the affected repository.
Are protected release tags still vulnerable?
No. Protected tag rules that cover the release tag block the deletion, even through the affected route.
What can be done if patching is not immediately possible?
Protect tags used by published releases. This prevents deletion of releases whose tags are covered by the protected tag rules.
What is the impact of successful exploitation?
An attacker can permanently delete published releases in the repository, including their attachments.