CVE-2026-0798
BaseFortify
Publication date: 2026-01-22
Last updated on: 2026-01-29
Assigner: Gitea Limited
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| gitea | gitea | to 1.25.4 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability occurs in Gitea where release notification emails for private repositories may still be sent to users who no longer have access. Specifically, when a repository is changed from public to private, users who previously watched the repository might continue to receive notifications about releases, potentially exposing release titles, tags, and content to unauthorized users.
How can this vulnerability impact me? :
The impact of this vulnerability is that sensitive information about private repository releases could be disclosed to users who should no longer have access. This could lead to unintended information leakage, potentially compromising confidentiality of release details and related content.