PT-2026-107309 · Gitea · Gitea

CVE-2026-97626

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Requesting a user or organization profile page (GET /{username}) with an Accept: application/rss+xml or Accept: application/atom+xml header returned the owner's activity feed without the visibility check that the profile page and the .rss and .atom routes apply. Anonymous users, restricted users and non-members could confirm the existence of limited or private users and private organizations and read their profile details and public activity, also when [other] ENABLE FEED was disabled. Activity in private repositories was not included.

Incorrect Authorization

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-97626

Produtos afetados

Gitea