CVE-2026-0798

Gitea Release Email Notifications Leak Private Repository Release Details After Access Revocation

Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content.


We have discovered 1,149 live websites that are affected by CVE-2026-0798.

Run a Free Instant Scan




Affected Software

Product  Gitea
Category Dev Tools
Vulnerable Domains1,149 live websites (98% of Gitea install base)
Vulnerable Versions
  • from 0 through 1.25.3
Vulnerable Versions Count42 versions ( 95% of all versions)


Common Weakness Enumeration

CWE-284 Improper Access Control



Details

  • Published - Jan 22, 2026
  • Updated - Jan 23, 2026

Credits

  • spingARbor (reporter)

Website Distribution by Country

Number of websites using CVE-2026-0798
United States248 websites



Germany337 websites
France160 websites
Russia68 websites
Singapore50 websites
China44 websites
Netherlands26 websites
GB21 websites
Canada18 websites

Website Distribution by TLD

Number of websites using CVE-2026-0798
.com258 websites
.de141 websites
.net124 websites
.org95 websites
.fr51 websites
.ru46 websites
.io21 websites
.eu21 websites
.nl14 websites
.info14 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-0798

Top websites that are affected by CVE-2026-0798. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.org France***,***
***.********.com United States***,***
*****.**********.eu GB***,***
***.******.com Switzerland***,***
***.*******.net United States***,***
******.fr France***,***
****.********.ch Switzerland*,***,***
*****.*******.org Germany*,***,***
***.*******.fi Finland*,***,***
***.*******.ca Canada*,***,***
See full domain list

FAQ

CVE-2026-0798 is Improper Access Control in Gitea
A total of 1,149 websites have been identified as vulnerable to CVE-2026-0798, based on global website indexing conducted by WebTechSurvey.
The Gitea is affected by the CVE-2026-0798 vulnerability.
Gitea versions up to and including 1.25.3 are vulnerable to CVE-2026-0798.