Количество 3
Количество 3
CVE-2026-20800
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications.
CVE-2026-20800
Gitea's notification API does not re-validate repository access permis ...
GHSA-2vgv-hgv4-22mh
Gitea improperly exposes issue and pull request titles
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-20800 Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications. | CVSS3: 6.5 | 0% Низкий | 17 дней назад | |
CVE-2026-20800 Gitea's notification API does not re-validate repository access permis ... | CVSS3: 6.5 | 0% Низкий | 17 дней назад | |
GHSA-2vgv-hgv4-22mh Gitea improperly exposes issue and pull request titles | 0% Низкий | 17 дней назад |
Уязвимостей на страницу