CVE-2026-0798
3.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Exploitability: 2.1 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content.
Affected (1)
References (4)
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Issue TrackingPatch
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Release Notes
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Broken Link
Timeline
No history available yet.