CVE-2025-68944
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-68944 is an access control bypass vulnerability in Gitea's package registry that stems from improper propagation of token scope, classified as a Confused Deputy problem (CWE-441). It affects all Gitea versions before 1.22.2 and was publicly disclosed on December 26, 2025. The vulnerability allows authenticated users to perform package upload operations beyond their intended token permissions in affected registries (NuGet, Conan, and container registries). It carries a CVSS v3.1 base score of 5.3 (Medium) per NVD, or 5.0 (Moderate) per the GitHub Advisory (Github Advisory, Red Hat Bugzilla).

Technical details

The root cause is CWE-441 (Unintended Proxy or Intermediary / 'Confused Deputy'), where Gitea fails to consistently enforce token scope restrictions during package upload operations in its NuGet, Conan, and container package registries. When a token with read-only package permissions is used, the scope is not correctly propagated through the access control logic, allowing the token to be treated as having broader write permissions than intended. The fix was implemented in pull request #31967, which corrected the scope-checking logic and added a dedicated function to avoid duplicated permission-checking code (Gitea PR #31967, Github Advisory).

Impact

Successful exploitation allows an authenticated attacker with a read-scoped token to upload or modify packages in Gitea's NuGet, Conan, or container registries beyond their authorized access level, compromising the integrity of those package registries. There is no confidentiality or availability impact — the vulnerability is limited to unauthorized write operations on package resources. In supply chain contexts, this could enable an attacker to inject malicious packages into registries that other users or CI/CD pipelines consume (Github Advisory, Red Hat Bugzilla).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The vulnerability requires valid authentication credentials (a Gitea account with at least a read-scoped token), limiting the attack surface to authenticated users. The EPSS score is approximately 0.013% (2nd percentile), indicating a low probability of near-term exploitation (Github Advisory, Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Mitigation and workarounds

Upgrade Gitea to version 1.22.2 or later, which includes the fix for token scope propagation in NuGet, Conan, and container package registries (Gitea Release v1.22.2). As interim measures, administrators should audit existing token permissions to ensure tokens are scoped to the minimum required access level, and monitor package registry upload activity for unexpected changes. No configuration-based workaround is available that fully mitigates the issue without upgrading.

Community reactions

The vulnerability received routine coverage from vulnerability tracking services and security feeds shortly after disclosure on December 26, 2025. Red Hat tracked it via Bugzilla and assigned it medium severity. No notable researcher commentary, vendor statements beyond the release notes, or significant social media discussion has been identified (Red Hat Bugzilla, Gitea Release v1.22.2).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13097HIGH8.7
  • NixOS logoNixOS
  • freeipa-common
NoYesAug 20, 2026
CVE-2026-73198HIGH7.5
  • NixOS logoNixOS
  • ctdb-ceph-mutex
NoYesAug 20, 2026
CVE-2026-73197HIGH7.5
  • NixOS logoNixOS
  • ipa-server-trust-ad
NoYesAug 20, 2026
CVE-2026-73196MEDIUM6.5
  • NixOS logoNixOS
  • freeipa-server-dns
NoYesAug 20, 2026
CVE-2026-64777MEDIUM4.3
  • NixOS logoNixOS
  • container
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management