CVE-2026-97626 PUBLISHED

Gitea profile feed disclosure bypassing user visibility

Assigner: Gitea
Reserved: 04.10.2026 Published: 06.10.2026 Updated: 06.10.2026

Requesting a user or organization profile page (GET /{username}) with an Accept: application/rss+xml or Accept: application/atom+xml header returned the owner's activity feed without the visibility check that the profile page and the .rss and .atom routes apply. Anonymous users, restricted users and non-members could confirm the existence of limited or private users and private organizations and read their profile details and public activity, also when [other] ENABLE_FEED was disabled. Activity in private repositories was not included.

Product Status

Vendor Gitea
Product Gitea
Versions Default: unaffected
  • affected from 0 to 28.0.0 (incl.)

Credits

  • https://github.com/tienpa99 reporter
  • https://github.com/Black1hp finder
  • https://github.com/Mon3mRT finder
  • https://github.com/silverwind remediation developer
  • https://github.com/bircni remediation developer

References

Problem Types

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE
  • CWE-863: Incorrect Authorization CWE