CVE-2026-20904 | Gitea up to 1.25.3 OpenID URI access control (GHSA-jrpc-w85r-hgqx / EUVD-2026-4262)
A vulnerability described as critical has been identified in Gitea up to 1.25.3. This issue affects some unknown processing of the component OpenID URI Handler. The manipulation results in improper access controls.
This vulnerability is reported as CVE-2026-20904. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.