Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j8xr-c56q-m8jj Gitea improperly exposes issue titles and repository names through previously started stopwatches
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 27 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 23 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Gitea
Gitea gitea
Vendors & Products Gitea
Gitea gitea

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches.
Title Gitea Stopwatch API Missing Authorization Check Leads to Post-Revocation Information Disclosure
Weaknesses CWE-284
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Gitea

Published:

Updated: 2026-01-23T21:54:21.705Z

Reserved: 2026-01-08T23:02:37.553Z

Link: CVE-2026-20883

cve-icon Vulnrichment

Updated: 2026-01-23T21:10:57.579Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-22T22:16:17.713

Modified: 2026-01-26T15:04:14.850

Link: CVE-2026-20883

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-01-22T22:01:50Z

Links: CVE-2026-20883 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-01-23T10:27:08Z

Weaknesses