CVE-2026-0798
Gitea vulnerability analysis and mitigation

Overview

CVE-2026-0798 is an improper access control vulnerability in Gitea that causes release notification emails for private repositories to be sent to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content. All Gitea versions prior to 1.25.4 are affected. The vulnerability was disclosed on January 22, 2026, with a patch released on January 23, 2026. It carries a CVSS v3.1 base score of 3.5 (Low) (Github Advisory, Feedly).

Technical details

The root cause is classified as CWE-284 (Improper Access Control): when a repository's visibility is changed from public to private, Gitea failed to clean up existing watch subscriptions for users who no longer have access, and did not perform permission checks before sending release notification emails (Github Advisory). The fix, implemented in pull request #36319, addresses both issues by cleaning watches when a repository is made private and adding permission checks in the release email mailer (services/mailer/mail_release.go) (Gitea PR). Exploitation requires that a user previously watched a public repository before it was converted to private, and that a new release is published after the conversion — no active attacker action is needed beyond having previously watched the repository.

Impact

The primary impact is confidentiality: unauthorized users who previously watched a now-private repository will receive release notification emails containing release titles, tag names, and release body content that they should no longer be able to access (Github Advisory). There is no integrity or availability impact. The scope is limited to information disclosure of release metadata; it does not expose source code, credentials, or allow any modification of repository data. Organizations that rely on repository privacy to protect sensitive release information (e.g., pre-announcement product details, internal versioning) are most at risk.

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The vulnerability is passive in nature — a former watcher simply receives emails they should not, without any active exploitation step required. The EPSS score is approximately 0.016–0.017%, placing it in the 4th percentile for exploitation likelihood (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported.

Mitigation and workarounds

Upgrade Gitea to version 1.25.4 or later, which cleans watch subscriptions when a repository is made private and enforces permission checks before sending release notification emails (Gitea Release, Gitea Blog). Gitea Cloud instances are automatically upgraded during the maintenance window. As a workaround for administrators unable to upgrade immediately, manually review and remove watch subscriptions for users who should no longer have access to repositories that have been converted from public to private, and audit release notification subscriptions for all private repositories (Github Advisory).

Community reactions

The Gitea project published a release blog post announcing v1.25.4 as a security release addressing this and several other vulnerabilities (Gitea Blog). The vulnerability received routine coverage in vulnerability tracking feeds and databases, with no notable researcher commentary or significant community discussion beyond standard disclosure channels.

Additional resources


SourceThis report was generated using AI

Related Gitea vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60004CRITICAL9.8
  • Gitea logoGitea
  • gitea
YesYesAug 26, 2026
CVE-2026-46603HIGH7.5
  • Tailscale logoTailscale
  • pdfcpu
NoYesAug 14, 2026
CVE-2026-56862HIGH7.5
  • cAdvisor logocAdvisor
  • cilium-cli
NoYesAug 13, 2026
CVE-2026-56859HIGH7.5
  • cAdvisor logocAdvisor
  • flux-2.6
NoYesAug 13, 2026
CVE-2026-56860MEDIUM5.9
  • cAdvisor logocAdvisor
  • cilium-1.19
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management