CVE-2026-96589: Gitea private repository access retained after rejected transfer

Published Oct 6, 2026
·
Updated

When a private repository is transferred to a user who lacks access, Gitea grants that recipient temporary read access as a collaborator so they can review the repository. Rejecting or cancelling the transfer did not revoke this collaboration, so the named recipient kept persistent read access to the private repository, including its code, issues, pull requests and wiki, and could clone it. The repository owner was not notified. Transfer-granted access is now removed while collaborations that existed before the transfer are preserved.

Affected Software

1 affected component
Gitea Gitea

Event History

Oct 6, 2026
CVE Published
via MITRE·07:25 PM
Data Sourced
via MITRE·07:25 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Will applying the fix remove collaborator access that existed before a repository transfer was attempted?

No. The change removes access granted for the transfer while preserving collaborations that existed before the transfer.

2

Does the recipient need to accept the transfer to retain access?

No. A recipient could retain read access after rejecting or cancelling the transfer, because the temporary collaborator access was not revoked.

3

What can a recipient with retained access view or do?

They can read the private repository's code, issues, pull requests, and wiki, and can clone the repository. The repository owner is not notified.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203