Description

In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.

INFO

Published Date :

2026-01-01T04:39:48.140Z

Last Modified :

2026-01-05T19:56:03.799Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-69413 vulnerability.

Vendors Products
Gitea
  • Gitea

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact