Webhook Security Flaw in Gitea Affects Repository Access Control
CVE-2026-58440

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-58440?

A serious vulnerability has been identified in Gitea, where webhooks initially set up by collaborators continue to activate even after their access to the repository has been revoked. This oversight results from incomplete revocation processes in the DeleteCollaboration function, allowing continuous unauthorized access and potential real-time exfiltration of sensitive private repository content. Users are urged to review their webhook configurations and ensure they are updated to mitigate the risk of data leaks.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sec-reex
.