Unrated severityNVD Advisory· Published Jul 3, 2026· Updated Jul 7, 2026
Gitea organization permission APIs expose private visibility information
CVE-2026-25712
Description
Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/go-gitea/gitea/pull/36798mitrepatch
- github.com/go-gitea/gitea/pull/36841mitrepatch
- blog.gitea.com/release-of-1.25.5/mitrerelease-notes
- github.com/go-gitea/gitea/releases/tag/v1.25.5mitrerelease-notes
News mentions
0No linked articles in our index yet.