{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97626","assignerOrgId":"88ee5874-cf24-4952-aea0-31affedb7ff2","state":"PUBLISHED","assignerShortName":"Gitea","dateReserved":"2026-10-04T22:02:04.885Z","datePublished":"2026-10-06T21:36:48.056Z","dateUpdated":"2026-10-06T21:36:48.056Z"},"containers":{"cna":{"providerMetadata":{"orgId":"88ee5874-cf24-4952-aea0-31affedb7ff2","shortName":"Gitea","dateUpdated":"2026-10-06T21:36:48.056Z"},"title":"Gitea profile feed disclosure bypassing user visibility","descriptions":[{"lang":"en","value":"Requesting a user or organization profile page (`GET /{username}`) with an `Accept: application/rss+xml` or `Accept: application/atom+xml` header returned the owner's activity feed without the visibility check that the profile page and the `.rss` and `.atom` routes apply. Anonymous users, restricted users and non-members could confirm the existence of limited or private users and private organizations and read their profile details and public activity, also when `[other] ENABLE_FEED` was disabled. Activity in private repositories was not included."}],"affected":[{"vendor":"Gitea","product":"Gitea","packageName":"gitea.dev","defaultStatus":"unaffected","versions":[{"version":"0","status":"affected","lessThanOrEqual":"28.0.0","versionType":"semver"}]}],"references":[{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-hf55-9cwq-2x64","name":"GitHub Security Advisory GHSA-hf55-9cwq-2x64","tags":["vendor-advisory"]},{"url":"https://github.com/go-gitea/gitea/pull/39501","name":"Fix: go-gitea/gitea pull request #39501","tags":["patch"]},{"url":"https://github.com/go-gitea/gitea/pull/39507","name":"Fix backport to release/v28: go-gitea/gitea pull request #39507","tags":["patch"]},{"url":"https://blog.gitea.com/release-of-28.1.0/","name":"Gitea 28.1.0 release announcement","tags":["release-notes"]},{"url":"https://github.com/go-gitea/gitea/releases/tag/v28.1.0","name":"go-gitea/gitea v28.1.0 release","tags":["release-notes"]}],"problemTypes":[{"descriptions":[{"lang":"en","type":"CWE","cweId":"CWE-200","description":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor"},{"lang":"en","type":"CWE","cweId":"CWE-863","description":"CWE-863: Incorrect Authorization"}]}],"credits":[{"lang":"en","value":"https://github.com/tienpa99","type":"reporter"},{"lang":"en","value":"https://github.com/Black1hp","type":"finder"},{"lang":"en","value":"https://github.com/Mon3mRT","type":"finder"},{"lang":"en","value":"https://github.com/silverwind","type":"remediation developer"},{"lang":"en","value":"https://github.com/bircni","type":"remediation developer"}]}}}