CVE-2026-20909: Gitea exposes tracked time entries without repository authorization
(updated )
Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
References
- blog.gitea.com/release-of-1.25.5
- github.com/advisories/GHSA-fhq3-p242-2qpf
- github.com/go-gitea/gitea/commit/00566cc953dba772d2f38aa475d235fead461605
- github.com/go-gitea/gitea/commit/ed57c70176a6cac63f48ddf6b0d5f4f72cfea963
- github.com/go-gitea/gitea/pull/36662
- github.com/go-gitea/gitea/pull/36744
- github.com/go-gitea/gitea/releases/tag/v1.25.5
- nvd.nist.gov/vuln/detail/CVE-2026-20909
Code Behaviors & Features
Detect and mitigate CVE-2026-20909 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →