Missing Authorization in Gitea - CVE-2026-50105
Published: July 14, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in RSS/Atom feed handlers when processing API-token Basic authentication requests for feed routes. A remote user can use a public-only or wrong-scope personal access token to disclose sensitive information.
The issue affects feed endpoints that expose private commit metadata, release or tag notes, and the token owner's private activity stream, while normal repository read checks are still enforced.