CVE-2026-20912
Gitea Release Attachment Ownership Validation Vulnerability.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
Gitea has a vulnerability where it fails to properly validate repository ownership when linking attachments to releases. This could allow an attachment from a private repository to be linked to a release in a public repository, potentially exposing sensitive data to unauthorized access.