Access Control Flaw in Gitea Notification API
CVE-2026-20800
6.5MEDIUM
What is CVE-2026-20800?
The notification API in Gitea has a significant access control vulnerability that permits users to access information about private repositories even after their permissions have been revoked. Specifically, this oversight allows previously received notifications to expose issue and pull request titles, compromising repository confidentiality. It's critical for Gitea users to be aware of this vulnerability to mitigate potential information leaks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Gitea Open Source Git Server 0 <= 1.25.3
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
spingARbor
