Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58440

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 7.5

Описание

Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in DeleteCollaboration)

A flaw was found in Gitea. Webhooks created by a collaborator continue to function even after their repository access is revoked. This incomplete revocation allows for the ongoing, real-time exfiltration of private repository content, leading to information disclosure.

Отчет

A flaw was found in Gitea's DeleteCollaboration function. When a collaborator's repository access is revoked, existing webhooks created by that user remain active instead of being disabled or removed. An attacker who previously held collaborator permissions can leverage these orphaned webhooks to continuously exfiltrate event payloads and sensitive private repository content without authorization.

Меры по смягчению последствий

To mitigate this vulnerability, repository administrators should manually audit and delete all webhooks created by a collaborator immediately upon revoking their access.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-controller-rhel9Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-459
https://bugzilla.redhat.com/show_bug.cgi?id=2515499gitea.dev: Gitea: Information disclosure via incomplete webhook revocation

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.8
nvd
20 дней назад

Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)

redos
20 дней назад

Уязвимость gitea

redos
20 дней назад

Уязвимость gitea

CVSS3: 6.8
github
около 1 месяца назад

Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content

7.5 High

CVSS3