Improper access control in Gitea - CVE-2026-67577
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the activity feed and heatmap API endpoints when handling requests for limited-visibility user data. A remote user can send crafted API requests to disclose sensitive information.
Exposed data can include repository names, push and commit events, full commit-message content, issue and pull request events, and contribution timestamps for limited-visibility users with qualifying public-repository activity.