CVE-2026-58419: Gitea: Notification API leaks private issue metadata after access revocation
An information disclosure issue in the Gitea Notification API allows users who have lost access to a private repository to continue accessing private issue or pull request information through existing notification threads. Although repository information is hidden after access revocation, the subject field remains accessible and continues to expose private metadata.
References
- blog.gitea.com/release-of-1.26.3-and-1.26.4
- github.com/advisories/GHSA-44qc-pgvp-wx7v
- github.com/go-gitea/gitea/commit/9e84deb969aff5c1115c2984e41250f28c78451f
- github.com/go-gitea/gitea/pull/38108
- github.com/go-gitea/gitea/releases/tag/v1.26.4
- github.com/go-gitea/gitea/security/advisories/GHSA-44qc-pgvp-wx7v
- nvd.nist.gov/vuln/detail/CVE-2026-58419
Code Behaviors & Features
Detect and mitigate CVE-2026-58419 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →