CVE-2026-0798: Gitea Release Email Notifications Leak Private Repository Release Details After Access Revocation
Published Jan 22, 2026
·Updated
Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content.
Affected Software
3 affected componentsFixes available
gitea/gitea
go/code.gitea.io/gitea<1.25.4
1.25.4
Gitea Gitea<1.25.4
Remediation
Patch Available
Event History
Jan 22, 2026
CVE Published
via MITRE·10:01 PM
Data Sourced
via MITRE·10:01 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 23, 2026
Advisory Published
via GitHub·12:31 AM
Data Sourced
via GitHub·12:31 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the CVE-2026-0798 severity level?
CVE-2026-0798 has been classified as a moderate severity vulnerability.
2
How do I resolve CVE-2026-0798?
To fix CVE-2026-0798, update Gitea to version 1.25.4 or later.
3
What is the impact of CVE-2026-0798?
CVE-2026-0798 can potentially expose release notification emails to users who no longer have access to private repositories.
4
Is CVE-2026-0798 specific to certain versions of Gitea?
Yes, CVE-2026-0798 affects versions of Gitea prior to 1.25.4.
5
Can CVE-2026-0798 be exploited remotely?
Yes, CVE-2026-0798 could be exploited by malicious users to gain information about private repository releases.