CVE-2026-105267: Gitea tag delete route deletes releases without release permission

Published Oct 6, 2026
·
Updated

The Gitea web route for deleting tags (POST /{owner}/{repo}/tags/delete) requires only write access to the Code unit, but shares its handler with release deletion and did not check that the target was a plain tag. A collaborator with Code write access and without Releases write access could permanently delete published releases of that repository, including their attachments. Protected tag rules covering the release tag still blocked the deletion.

Affected Software

1 affected component
Gitea Gitea

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Configure protected tag rules covering the repository's release tag to block tag deletion.

    Gitea Protected tag rules = Cover the release tag

Event History

Oct 6, 2026
CVE Published
via MITRE·09:35 PM
Data Sourced
via MITRE·09:35 PM
DescriptionWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A collaborator who has write access to the repository's Code unit but does not have write access to Releases can exploit it. The collaborator must be able to use the web tag-deletion route for the affected repository.

2

Are protected release tags still vulnerable?

No. Protected tag rules that cover the release tag block the deletion, even through the affected route.

3

What can be done if patching is not immediately possible?

Protect tags used by published releases. This prevents deletion of releases whose tags are covered by the protected tag rules.

4

What is the impact of successful exploitation?

An attacker can permanently delete published releases in the repository, including their attachments.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203