Cross-Repository Information Leakage in Gitea by Go-Gitea
CVE-2026-57897

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-57897?

A cross-repository information disclosure vulnerability has been identified in Gitea, allowing unauthorized access to sensitive data through the Org-Level Actions Run and Job APIs. This flaw can potentially expose information across different repositories, risking private data leakages. Users of affected versions should prioritize upgrading to mitigate risks associated with this vulnerability.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

prakhar0x01
.