PT-2026-63312 · Gitea+1 · Gitea+1

·

CVE-2026-58510

·

Published

2026-07-21

·

Updated

2026-08-26

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gitea versions 1.25.4 through 2026-05-16
Description When a public repository is changed to private via the REST API, watch records are not properly cleared. This occurs because the updateRepository() function, which is utilized by the PATCH /api/v1/repos/{owner}/{repo} endpoint, fails to call the ClearRepoWatches function, unlike the web UI path. Consequently, users whose access has been revoked can still see the now-private repository in the GET /api/v1/user/subscriptions?private=true endpoint, exposing sensitive metadata such as the repository description, default branch, language, and license list. Additionally, this issue allows the NumWatches counter to remain inflated and creates a potential for content leakage through future notification paths that may lack proper access checks.
Recommendations In the updateRepository() function within services/repository/repository.go, add a call to ClearRepoWatches immediately after ClearRepoStars when a repository is set to private. As a temporary mitigation, avoid using the PATCH /api/v1/repos/{owner}/{repo} endpoint to change repository visibility to private and use the web UI Settings instead.

Exploit

Fix

DoS

Information Disclosure

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58510
GHSA-Q423-49RW-G9MH
GO-2026-6069
OPENSUSE-SU-2026:21551-1
SUSE-SU-2026:23216-1
SUSE-SU-2026:23227-1

Affected Products

Gitea
Red Os