CVE-2026-96589: Gitea private repository access retained after rejected transfer
When a private repository is transferred to a user who lacks access, Gitea grants that recipient temporary read access as a collaborator so they can review the repository. Rejecting or cancelling the transfer did not revoke this collaboration, so the named recipient kept persistent read access to the private repository, including its code, issues, pull requests and wiki, and could clone it. The repository owner was not notified. Transfer-granted access is now removed while collaborations that existed before the transfer are preserved.
Affected Software
Event History
Frequently Asked Questions
Will applying the fix remove collaborator access that existed before a repository transfer was attempted?
No. The change removes access granted for the transfer while preserving collaborations that existed before the transfer.
Does the recipient need to accept the transfer to retain access?
No. A recipient could retain read access after rejecting or cancelling the transfer, because the temporary collaborator access was not revoked.
What can a recipient with retained access view or do?
They can read the private repository's code, issues, pull requests, and wiki, and can clone the repository. The repository owner is not notified.