CVE-2026-0798

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
22/01/2026
Last modified:
29/01/2026

Description

Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:* 1.25.4 (excluding)