Visibility Flaw in Gitea Allows Profile Information Exposure
CVE-2026-97626

Currently unrated

Key Information:

Vendor

Gitea

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-97626?

A flaw in Gitea's handling of user profile pages allows unauthorized access to sensitive information. When a user requests a profile page with specific content types, the system fails to enforce visibility checks. This oversight enables not only anonymous users but also restricted users and non-members to access limited or private user profiles and their activity feeds. Even when the configuration to disable feeds is enabled, their existence and certain details are still revealed, posing a significant data privacy risk.

Affected Version(s)

Gitea 0 <= 28.0.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

https://github.com/tienpa99
https://github.com/Black1hp
https://github.com/Mon3mRT
https://github.com/silverwind
https://github.com/bircni
.