Webhook Security Flaw in Gitea Affects Repository Access Control
CVE-2026-58440
Currently unrated
What is CVE-2026-58440?
A serious vulnerability has been identified in Gitea, where webhooks initially set up by collaborators continue to activate even after their access to the repository has been revoked. This oversight results from incomplete revocation processes in the DeleteCollaboration function, allowing continuous unauthorized access and potential real-time exfiltration of sensitive private repository content. Users are urged to review their webhook configurations and ensure they are updated to mitigate the risk of data leaks.
Affected Version(s)
Gitea Open Source Git Server 0 <= 1.26.4
