Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
•••
Malware / Trojaner / VirenMalware trends in first half of 2026(25.09.2026 um 13:08 Uhr)
•••
Linux Tipps & HardeningWelcome Tamás Zolnai, new LibreOffice Online developer(26.09.2026 um 15:49 Uhr)
•
Linux Tipps & HardeningHappy 43rd birthday GNU!(27.09.2026 um 01:11 Uhr)
••
Sichere ProgrammierungNative Document Export (anyconvert)(27.09.2026 um 12:44 Uhr)
••••
Malware / Trojaner / VirenMalware trends in first half of 2026(25.09.2026 um 13:08 Uhr)
•••
Linux Tipps & HardeningWelcome Tamás Zolnai, new LibreOffice Online developer(26.09.2026 um 15:49 Uhr)
•
Linux Tipps & HardeningHappy 43rd birthday GNU!(27.09.2026 um 01:11 Uhr)
••
Sichere ProgrammierungNative Document Export (anyconvert)(27.09.2026 um 12:44 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

CVE-2026-0798: Gitea's Ghost in the Machine: Leaking Private Release Notes via Zombie Watchers

Gitea's Ghost in the Machine: Leaking Private Release Notes via Zombie Watchers Vulnerability ID: CVE-2026-0798 CVSS Score: 3.5 Published: 2026-01-23 A logic flaw in Gitea's notification system allowed unauthorized users—specifically '…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




Gitea's Ghost in the Machine: Leaking Private Release Notes via Zombie Watchers




Vulnerability ID: CVE-2026-0798

CVSS Score: 3.5

Published: 2026-01-23




A logic flaw in Gitea's notification system allowed unauthorized users—specifically 'watchers' who lost access or remained subscribed after a repository went private—to continue receiving detailed release emails containing private changelogs and tags.






TL;DR



If you fire an employee and revoke their Git access, they might still be watching your repo. In Gitea versions prior to 1.25.4, the release mailer didn't double-check permissions before hitting 'Send'. This resulted in private release notes, titles, and tags being broadcast to users who should have been locked out. The fix ensures permissions are validated at the moment of dispatch and wipes the watcher list when a repo goes private.









Technical Details





  • CWE: CWE-284 (Improper Access Control)


  • CVSS v3.1: 3.5 (Low)


  • Attack Vector: Network


  • Attack Complexity: Low


  • Privileges Required: Low (Requires previous access)


  • Impact: Information Disclosure






Affected Systems




  • Gitea < 1.25.4


  • Gitea: <= 1.25.3 (Fixed in: 1.25.4)






Code Analysis






Commit: b477610



Fix release notification permission check




func MakeRepoPrivate... repo_model.ClearRepoWatches(ctx, repo.ID)









Exploit Details





  • N/A: No public exploit code needed; logic flaw is exploited by configuration state.






Mitigation Strategies




  • Upgrade Gitea immediately to version 1.25.4 or later.

  • If upgrading is not possible, manually audit the 'watchers' list on sensitive private repositories.

  • Advise developers not to include sensitive credentials or specific architectural secrets in release notes.



Remediation Steps:




  1. Pull the latest docker image: docker pull gitea/gitea:1.25.4

  2. Restart the Gitea service.

  3. Verify the fix by revoking a test user's access and ensuring they do not receive subsequent release emails.






References








Read the full report for CVE-2026-0798 on our website for more details including interactive diagrams and full exploit analysis.

2. Cyber Threat Intelligence & Forensik

IoC Intelligence (1 Indikatoren)
CVE-2026-0798
CTI Threat Relationship Graph3 Knoten / 2 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
Exploit & Remediation Lifecycle Timeline
CVE-2026-0798
Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Öffentlicher Nachweis/Code verfügbar (Exploit-DB/EUVD)
In-the-Wild Ausnutzung
Keine Massenausnutzung gemeldet
Patch & Schutzmaßnahmen
Upstream-Patch-Referenz vorhanden (Commit-/Advisory-Link)
Exploit Weaponization & Public PoC Radar
ELEVATED · Index 15/100
Exploit-DB
Kein EDB-Eintrag
Interaktion
Interaktion nötig
Authentifizierung
Erforderlich

3. Compliance, SLA & Vendor Adherence

CVSS 3.5CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Impact: 1.41 | Exploitability: 2.07
AVN
Netzwerk (Remote)
Aus der Ferne über das Internet ohne Vorbedingungen exploitbar.
ACL
Niedrig (Low)
Wiederholbar und deterministisch ohne spezielle Race Conditions ausnutzbar.
PRL
Niedrig (Standard-Benutzer)
Erfordert Anmeldedaten eines regulären Benutzers.
UIR
Erforderlich (Click/Phishing)
Ein Opfer muss eine präparierte Datei öffnen oder einen Link anklicken.
SU
Unverändert (Scope Unchanged)
Auswirkungen verbleiben isoliert in der angreifbaren Anwendungskomponente.
CL
Gering (Teilabfluss)
Teilweiser oder kein Datenabfluss.
IN
Keine
Teilweise oder keine Manipulation.
AN
Keine
Teilweise oder keine Beeinträchtigung.
BSI-Warnung (Deutschland)CVE-2026-0798
Gitea: Mehrere Schwachstellen22.01.2026
CISA-SSVC-Triage (vulnrichment)CVE-2026-0798
Exploitation: none (Keine bekannte Ausnutzung)Automatable: no (Nicht automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2026-01-23T16:47:54.364105Z · CISA Coordinator
Advisory Radar

Hersteller-Sicherheitsmeldungen & Patch-Status

In herstellerseitiger Prüfung
Handlungsempfehlung für Administratoren

Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.

Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten CVE-2026-0798: Gitea's Ghost in the Machine: Leaking Private Release Notes via Zombie Watchers

Thematisch verwandte Begriffe: CVE20260798, Giteas, Ghost, Machine · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-101916 | @grpc/grpc-js implements the core functionality of gRPC purely in JavaS…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag