ZeroHour

CVE-2026-0798

CVSS 3.1
3.5 low
EPSS
<1%p15
Published
()
Modified
Description

Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content.

Vendors
gitea
Products
gitea
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.