VYPR
Unrated severityNVD Advisory· Published Oct 6, 2026

CVE-2026-97626

CVE-2026-97626

Description

Requesting a user or organization profile page (GET /{username}) with an Accept: application/rss+xml or Accept: application/atom+xml header returned the owner's activity feed without the visibility check that the profile page and the .rss and .atom routes apply. Anonymous users, restricted users and non-members could confirm the existence of limited or private users and private organizations and read their profile details and public activity, also when [other] ENABLE_FEED was disabled. Activity in private repositories was not included.

Affected products

1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.