Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8fwc-qjw5-rvgp | Gitea may send release notification emails for private repositories to users whose access has been revoked |
Thu, 29 Jan 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:* |
Tue, 27 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-497 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 23 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 23 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitea
Gitea gitea |
|
| Vendors & Products |
Gitea
Gitea gitea |
Thu, 22 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content. | |
| Title | Gitea Release Email Notifications Leak Private Repository Release Details After Access Revocation | |
| Weaknesses | CWE-284 | |
| References |
|
Status: PUBLISHED
Assigner: Gitea
Published:
Updated: 2026-01-23T16:49:04.309Z
Reserved: 2026-01-08T23:02:08.534Z
Link: CVE-2026-0798
Updated: 2026-01-23T16:48:29.754Z
Status : Analyzed
Published: 2026-01-22T22:16:15.957
Modified: 2026-01-29T21:59:24.397
Link: CVE-2026-0798
OpenCVE Enrichment
Updated: 2026-04-18T03:45:21Z
Github GHSA