PT-2026-4290 · Gitea+1 · Gitea+1

Spingarbor

·

Published

2026-01-22

·

Updated

2026-02-24

·

CVE-2026-20883

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gitea (affected versions not specified)
Description The stopwatch API in Gitea does not re-validate repository access permissions. This means that if a user’s access to a private repository is revoked, they may still be able to view issue titles and repository names through previously started stopwatches. The issue affects the ability to control access to repository information after permissions have been changed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-GITEA-2026-20883
CVE-2026-20883
GHSA-644V-XV3J-XGQG
GHSA-J8XR-C56Q-M8JJ
GO-2026-4368
SUSE-SU-2026:0403-1

Affected Products

Gitea
Red Os