CVE-2026-0798 is a low-severity vulnerability affecting Gitea, where users who previously watched a public repository may continue to receive release notification emails after the repository is made private. This could lead to the unintended disclosure of release titles, tags, and content to unauthorized individuals. The vulnerability has a CVSS score of 3.5 (LOW), indicating a low attack complexity and limited impact on confidentiality. There is currently no evidence of active exploitation, and no public exploit code or Metasploit/Nuclei modules are available. Despite its low severity, the CVE has garnered significant community discussion with 10 mentions, suggesting awareness among security professionals.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.25.4CPE matchmatch criteria | cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.