Improper access control in Gitea - CVE-2026-71301
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the markup preview route when resolving same-repository pull request references. A remote user can send a specially crafted POST request to disclose sensitive information.
Only pull request titles and displayed state are exposed; bodies, comments, and attachments are not returned.