Information disclosure in Gitea - CVE-2026-55982

 

Information disclosure in Gitea - CVE-2026-55982

Published: July 14, 2026


Vulnerability identifier: #VU137426
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55982
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the OIDC userinfo endpoint when handling bearer-authenticated requests with API tokens. A remote user can send a request with a narrowly scoped personal access token to disclose sensitive information.

The issue is limited to identity claims associated with the authenticated user, including email address and group membership information.


Affected software

Gitea

How to mitigate CVE-2026-55982

Install security update from vendor's website.

Gitea - update to 1.27.0

External References

Related Security Bulletins