PT-2026-107309 · Gitea · Gitea

CVE-2026-97626

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Requesting a user or organization profile page (GET /{username}) with an Accept: application/rss+xml or Accept: application/atom+xml header returned the owner's activity feed without the visibility check that the profile page and the .rss and .atom routes apply. Anonymous users, restricted users and non-members could confirm the existence of limited or private users and private organizations and read their profile details and public activity, also when [other] ENABLE FEED was disabled. Activity in private repositories was not included.

Incorrect Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97626

Affected Products

Gitea