UNKNOWN Go

Gitea improperly exposes issue titles and repository names through previously started stopwatches

GHSA-j8xr-c56q-m8jj · BIT-gitea-2026-20883 · CVE-2026-20883 · GHSA-644v-xv3j-xgqg · GO-2026-4368

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches.

Ready to move

Start Securing

Free, no credit card | First findings in minutes