REDHAT-BUG-2432204: Gitea Gitea vulnerability
Published Jan 22, 2026
·Updated
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.
Affected Software
1 affected component
Gitea Gitea
Event History
Jan 22, 2026
Data Sourced
via Red Hat·11:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2432204?
The severity of REDHAT-BUG-2432204 is rated as risk 23.
2
How do I fix REDHAT-BUG-2432204?
To fix REDHAT-BUG-2432204, ensure you update Gitea to the latest version that includes the patch for this vulnerability.
3
What does REDHAT-BUG-2432204 affect?
REDHAT-BUG-2432204 affects Gitea by allowing improper deletion of Git LFS locks associated with different repositories.
4
Who is impacted by REDHAT-BUG-2432204?
Users with write access to one repository are impacted as they can potentially delete LFS locks belonging to other repositories due to the vulnerability.
5
When was REDHAT-BUG-2432204 published?
REDHAT-BUG-2432204 was published on January 22, 2026.