In Gitea versions before 1.25.2 a medium severity vulnerability CVE-2025-69413 was detected. This vulnerability allows attackers to enumerate valid usernames by observing different responses from the /api/v1/user endpoint during failed authentication attempts, depending on whether a username exists. To address this issue, users should upgrade Gitea to version 1.25.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-69413.