REST API Exposure in Gitea by Gitea Vendor
CVE-2026-58417

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-58417?

A flaw in the REST API of Gitea allows unauthorized public access to organization membership details of private organizations. This vulnerability poses a significant risk as it can lead to the unintended disclosure of sensitive organizational information. Users are urged to review the latest security advisories and update to the patched versions to safeguard their data.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

maluff
Sai2r
mgelde
.