CVE-2026-58507: Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint
| Field | Value |
|---|---|
| Affected File | routers/web/repo/githttp.go, services/context/repo.go |
| Affected Functions | httpBase(), EarlyResponseForGoGetMeta() |
| Affected Lines | githttp.go:63–66, services/context/repo.go:374–396 |
| Prerequisite | None — fully unauthenticated |
References
Code Behaviors & Features
Detect and mitigate CVE-2026-58507 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →