CVE-2026-0798

LOW3.5EPSS 0.02%

Gitea may send release notification emails for private repositories to users whose access has been revoked

Published: 1/23/2026Modified: 2/3/2026
Also known as:GHSA-8fwc-qjw5-rvgpGHSA-f4wq-6ww5-m56pBIT-gitea-2026-0798GO-2026-4365

Description

Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
osvCVSS 3.1LOW3.5CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

References (8)