Private Repository Disclosure in Gitea by Go Gitea
CVE-2026-58507

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-58507?

The vulnerability allows unauthorized users to infer the existence of private repositories via the go-get meta endpoint. This can lead to potential information leakage about private projects, increasing the risk of targeted attacks. It is crucial for administrators to update to the latest version to mitigate this exposure.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

prakhar0x01
.