Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
02 / AFFECTED SOFTWARE
Affected packages
43 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches.
Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches.
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches.
05 / REFERENCES
Further evidence
- https://blog.gitea.com/release-of-1.25.4/
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/20xxx/CVE-2026-20883.json
- https://github.com/go-gitea/gitea/pull/36340
- https://github.com/go-gitea/gitea/pull/36368
- https://github.com/go-gitea/gitea/releases/tag/v1.25.4
- https://github.com/go-gitea/gitea/security/advisories/GHSA-644v-xv3j-xgqg
- https://nvd.nist.gov/vuln/detail/CVE-2026-20883
- https://blog.gitea.com/release-of-1.25.4
- https://github.com/advisories/GHSA-j8xr-c56q-m8jj
- https://github.com/go-gitea/gitea/commit/95ea2df00a70176c516b12f3cfee8c84a310280f
- https://pkg.go.dev/github.com/go-gitea/gitea