CVE-2026-0798: Gitea

Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content.

Affected products

  • Gitea Gitea: before 1.25.4 (fixed in 1.25.4)

Published 2026-01-22. Last modified 2026-06-17.