CVE-2026-97626
Received Received - Intake

Activity Feed Exposure in GitLab Profile Pages

Vulnerability report for CVE-2026-97626, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: Gitea Limited

Description

Requesting a user or organization profile page (`GET /{username}`) with an `Accept: application/rss+xml` or `Accept: application/atom+xml` header returned the owner's activity feed without the visibility check that the profile page and the `.rss` and `.atom` routes apply. Anonymous users, restricted users and non-members could confirm the existence of limited or private users and private organizations and read their profile details and public activity, also when `[other] ENABLE_FEED` was disabled. Activity in private repositories was not included.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Gitea Gitea 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows unauthorized users to access restricted profile details and activity feeds of users or organizations by requesting their profile page with specific HTTP headers. Normally, these details are protected by visibility checks, but the flaw bypasses those checks when the Accept header is set to application/rss+xml or application/atom+xml.

Impact Analysis

If you are a user or organization owner, attackers could confirm your existence even if your profile is private, view your public activity, and read profile details. If you are an administrator, this could expose sensitive information about restricted users or private organizations.

Mitigation Strategies

Update Gitea to the latest version to ensure the visibility check is applied to all profile page requests including those with RSS or Atom headers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97626. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart