Skip to main content
LOW

CVE-2026-0798

Gitea Release Email Notifications Leak Private Repository Release Details After Access Revocation

CVSS v3

3.5

LOW

EPSS Score

0.0 %

exploit probability

CISA KEV

No

known exploited

Exploitation

none

SSVC status

Description

Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content.

Technical details

CVSS v3 Vector
3.1
Published
2026-01-22
Last Modified
2026-01-29

Frequently asked questions

What is CVE-2026-0798?

Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content.

Is CVE-2026-0798 actively exploited?

Active exploitation of CVE-2026-0798 has not been confirmed. The EPSS score is 0.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-0798?

CVE-2026-0798 has a CVSS v3 base score of 3.5 (LOW severity), with vector string 3.1.

Is CVE-2026-0798 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key