CVE-2026-97626
Gitea profile feed disclosure bypassing user visibility
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Requesting a user or organization profile page (`GET /{username}`) with an `Accept: application/rss+xml` or `Accept: application/atom+xml` header returned the owner's activity feed without the visibility check that the profile page and the `.rss` and `.atom` routes apply. Anonymous users, restricted users and non-members could confirm the existence of limited or private users and private organizations and read their profile details and public activity, also when `[other] ENABLE_FEED` was disabled. Activity in private repositories was not included.
| CWE | CWE-200 CWE-863 |
| Vendor | gitea |
| Product | gitea |
| Published | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for gitea gitea
Be the first to know when new unknown vulnerabilities affecting gitea gitea are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Gitea / Gitea
0 โค 28.0.0
References
github.com: https://github.com/go-gitea/gitea/security/advisories/GHSA-hf55-9cwq-2x64 github.com: https://github.com/go-gitea/gitea/pull/39501 github.com: https://github.com/go-gitea/gitea/pull/39507 blog.gitea.com: https://blog.gitea.com/release-of-28.1.0/ github.com: https://github.com/go-gitea/gitea/releases/tag/v28.1.0
Credits
๐ https://github.com/tienpa99 https://github.com/Black1hp https://github.com/Mon3mRT https://github.com/silverwind https://github.com/bircni