Visibility Flaw in Gitea Allows Profile Information Exposure
CVE-2026-97626
Currently unrated
What is CVE-2026-97626?
A flaw in Gitea's handling of user profile pages allows unauthorized access to sensitive information. When a user requests a profile page with specific content types, the system fails to enforce visibility checks. This oversight enables not only anonymous users but also restricted users and non-members to access limited or private user profiles and their activity feeds. Even when the configuration to disable feeds is enabled, their existence and certain details are still revealed, posing a significant data privacy risk.
Affected Version(s)
Gitea 0 <= 28.0.0
