CVE-2025-68940

In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.


We have discovered 473 live websites that are affected by CVE-2025-68940.

Run a Free Instant Scan




Affected Software

Product  Gitea
Category Dev Tools
Vulnerable Domains473 live websites (42% of Gitea install base)
Vulnerable Versions
  • from 0 through 1.22.5
Vulnerable Versions Count21 versions ( 49% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Dec 26, 2025
  • Updated - Dec 26, 2025

Website Distribution by Country

Number of websites using CVE-2025-68940
United States98 websites



Germany146 websites
France82 websites
Russia33 websites
Singapore17 websites
Netherlands10 websites
Canada9 websites
Czech Republic7 websites
Switzerland7 websites

Website Distribution by TLD

Number of websites using CVE-2025-68940
.com94 websites
.de71 websites
.net51 websites
.org43 websites
.fr23 websites
.ru16 websites
.eu8 websites
.io8 websites
.info7 websites
.it7 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-68940

Top websites that are affected by CVE-2025-68940. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.******.com Switzerland***,***
***.*******.net United States***,***
******.fr France***,***
****.********.ch Switzerland*,***,***
***.*******.ca Canada*,***,***
***.************.com France*,***,***
*****************.xn--p1ai Russia*,***,***
****.*****.de Germany*,***,***
******.*************.de Germany*,***,***
***.*******.com Germany*,***,***
See full domain list

FAQ

CVE-2025-68940 is Incorrect Authorization in Gitea
A total of 473 websites have been identified as vulnerable to CVE-2025-68940, based on global website indexing conducted by WebTechSurvey.
The Gitea is affected by the CVE-2025-68940 vulnerability.
Gitea versions up to 1.22.5 are vulnerable to CVE-2025-68940.
CVE-2025-68940 is resolved in version 1.22.5 of Gitea.