๐Ÿ” CVE Alert

CVE-2026-97626

UNKNOWN 0.0

Gitea profile feed disclosure bypassing user visibility

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Requesting a user or organization profile page (`GET /{username}`) with an `Accept: application/rss+xml` or `Accept: application/atom+xml` header returned the owner's activity feed without the visibility check that the profile page and the `.rss` and `.atom` routes apply. Anonymous users, restricted users and non-members could confirm the existence of limited or private users and private organizations and read their profile details and public activity, also when `[other] ENABLE_FEED` was disabled. Activity in private repositories was not included.

CWE CWE-200 CWE-863
Vendor gitea
Product gitea
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for gitea gitea

Be the first to know when new unknown vulnerabilities affecting gitea gitea are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Gitea / Gitea
0 โ‰ค 28.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/go-gitea/gitea/security/advisories/GHSA-hf55-9cwq-2x64 github.com: https://github.com/go-gitea/gitea/pull/39501 github.com: https://github.com/go-gitea/gitea/pull/39507 blog.gitea.com: https://blog.gitea.com/release-of-28.1.0/ github.com: https://github.com/go-gitea/gitea/releases/tag/v28.1.0

Credits

๐Ÿ” https://github.com/tienpa99 https://github.com/Black1hp https://github.com/Mon3mRT https://github.com/silverwind https://github.com/bircni