« Volver al listado

CVE-2026-20800

Estado: AnalizadaMedia (6.5)—

Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-20800",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-20800",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-23T21:11:32.615971Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "88ee5874-cf24-4952-aea0-31affedb7ff2",
      "affectedData": [
        {
          "vendor": "Gitea",
          "product": "Gitea Open Source Git Server",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "1.25.3"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-01-22T22:16:17.540",
  "references": [
    {
      "url": "https://blog.gitea.com/release-of-1.25.4/",
      "tags": [
        "Release Notes"
      ],
      "source": "88ee5874-cf24-4952-aea0-31affedb7ff2"
    },
    {
      "url": "https://github.com/go-gitea/gitea/pull/36339",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "88ee5874-cf24-4952-aea0-31affedb7ff2"
    },
    {
      "url": "https://github.com/go-gitea/gitea/releases/tag/v1.25.4",
      "tags": [
        "Release Notes"
      ],
      "source": "88ee5874-cf24-4952-aea0-31affedb7ff2"
    },
    {
      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-g54m-9f6g-wj7q",
      "tags": [
        "Broken Link"
      ],
      "source": "88ee5874-cf24-4952-aea0-31affedb7ff2"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "88ee5874-cf24-4952-aea0-31affedb7ff2",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications."
    },
    {
      "lang": "es",
      "value": "La API de notificaciones de Gitea no revalida los permisos de acceso al repositorio al devolver los detalles de la notificación. Después de que se revoque el acceso de un usuario a un repositorio privado, aún pueden ver los títulos de las incidencias y las solicitudes de extracción a través de notificaciones recibidas previamente."
    }
  ],
  "lastModified": "2026-06-17T10:17:48.227",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFCB7D74-331D-4582-AB41-113A25BE8FAA",
              "versionEndExcluding": "1.25.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "88ee5874-cf24-4952-aea0-31affedb7ff2"
}