CVE-2026-97626 Details
Description
Requesting a user or organization profile page (`GET /{username}`) with an `Accept: application/rss+xml` or `Accept: application/atom+xml` header returned the owner's activity feed without the visibility check that the profile page and the `.rss` and `.atom` routes apply. Anonymous users, restricted users and non-members could confirm the existence of limited or private users and private organizations and read their profile details and public activity, also when `[other] ENABLE_FEED` was disabled. Activity in private repositories was not included.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://blog.gitea.com/release-of-28.1.0/ | Gitea Limited | |
| https://github.com/go-gitea/gitea/pull/39501 | Gitea Limited | |
| https://github.com/go-gitea/gitea/pull/39507 | Gitea Limited | |
| https://github.com/go-gitea/gitea/releases/tag/v28.1.0 | Gitea Limited | |
| https://github.com/go-gitea/gitea/security/advisories/GHSA-hf55-9cwq-2x64 | Gitea Limited |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | Gitea Limited |
| CWE-863 | Incorrect Authorization | Gitea Limited |
Affected Products
No affected product data is available for this CVE.
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Oct 6, 2026 | New CVE Received | Gitea Limited |