CVE-2026-20888: Gitea Pull Requests Auto-Merge: Read-Only Users Can Cancel Scheduled Auto-Merge via Web Endpoint (Authorization Bypass)
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20888?
CVE-2026-20888 has a medium severity rating due to unauthorized cancellation of scheduled auto-merges by read-only users.
How do I fix CVE-2026-20888?
To mitigate CVE-2026-20888, upgrade Gitea to version 1.25.4 or later, which includes fixes for the authorization bypass.
Who is affected by CVE-2026-20888?
CVE-2026-20888 affects Gitea users who have read access to pull requests, allowing them to exploit the auto-merge cancellation feature.
What type of vulnerability is CVE-2026-20888?
CVE-2026-20888 is classified as an authorization bypass vulnerability in the Gitea pull request auto-merge functionality.
Is CVE-2026-20888 present in older versions of Gitea?
Yes, CVE-2026-20888 is present in versions of Gitea prior to 1.25.4.