CVE-2026-0798
Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repos
Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content.
LOW · CVSS 3.5
EPSS 0.00017
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0