CVE 3.5 LOW

Gitea Release Email Notifications Leak Private Repository Release Details After Access Revocation_CVE-2026-0798

3.5 / 10
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Description

Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content.

Basic Information

ID CVE-2026-0798
Source Gitea
Published Jan 22, 2026 at 22:01
Modified Jan 23, 2026 at 16:49

Affected Product

Vendor Gitea
Product Gitea Open Source Git Server
Affected Versions Gitea Gitea Open Source Git Server 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.