CVE-2026-20904

medium Red Hat
CVSS v3 Base Score
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Published: January 22, 2026
Last Modified: January 22, 2026
Vendor: Red Hat

Description

Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.

CWE

CWE-639

Affected Products

OpenShift Pipelines

References