Gitea: Webhook Authorization Header Returned in Plaintext via API (CVE-2026-58511)
Gitea versions prior to 1.27.0 have a vulnerability where webhook authorization headers, although stored encrypted in the database, are decrypted and returned in plaintext through certain API endpoints. This exposure allows repository or site administrators to view sensitive authorization headers such as Bearer tokens, Basic authentication credentials, and API keys set by other admins. The vulnerability affects multiple API endpoints that return webhook details and compromises the intended encryption-at-rest protection by revealing secrets in API responses.
AI Analysis
Technical Summary
Gitea before version 1.27.0 contains a vulnerability (CVE-2026-58511) in which webhook authorization headers are stored encrypted but are decrypted and exposed in plaintext via certain API endpoints accessible to repository or site administrators. This issue allows authorized admins to view sensitive authorization credentials of other admins, including Bearer tokens, Basic auth credentials, and API keys. The vulnerability affects multiple API endpoints that return webhook details, undermining encryption-at-rest protections by exposing secrets in API responses.
Potential Impact
The vulnerability allows repository or site administrators to access sensitive authorization headers in plaintext, potentially exposing Bearer tokens, Basic authentication credentials, and API keys used by other administrators. This exposure could lead to unauthorized use of these credentials if an admin account is compromised or misused. However, the vulnerability requires high privileges (repository or site admin) to exploit and does not affect confidentiality beyond authorized admins. There is no impact on integrity or availability reported.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade Gitea to version 1.27.0 or later to prevent the plaintext exposure of webhook authorization headers. Since the vulnerability requires repository or site admin privileges to access, limiting admin access and applying the official fix will mitigate the risk.
Gitea: Webhook Authorization Header Returned in Plaintext via API (CVE-2026-58511)
Description
Gitea versions prior to 1.27.0 have a vulnerability where webhook authorization headers, although stored encrypted in the database, are decrypted and returned in plaintext through certain API endpoints. This exposure allows repository or site administrators to view sensitive authorization headers such as Bearer tokens, Basic authentication credentials, and API keys set by other admins. The vulnerability affects multiple API endpoints that return webhook details and compromises the intended encryption-at-rest protection by revealing secrets in API responses.
CVSS v3.1
Score 2.7low
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Gitea before version 1.27.0 contains a vulnerability (CVE-2026-58511) in which webhook authorization headers are stored encrypted but are decrypted and exposed in plaintext via certain API endpoints accessible to repository or site administrators. This issue allows authorized admins to view sensitive authorization credentials of other admins, including Bearer tokens, Basic auth credentials, and API keys. The vulnerability affects multiple API endpoints that return webhook details, undermining encryption-at-rest protections by exposing secrets in API responses.
Potential Impact
The vulnerability allows repository or site administrators to access sensitive authorization headers in plaintext, potentially exposing Bearer tokens, Basic authentication credentials, and API keys used by other administrators. This exposure could lead to unauthorized use of these credentials if an admin account is compromised or misused. However, the vulnerability requires high privileges (repository or site admin) to exploit and does not affect confidentiality beyond authorized admins. There is no impact on integrity or availability reported.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade Gitea to version 1.27.0 or later to prevent the plaintext exposure of webhook authorization headers. Since the vulnerability requires repository or site admin privileges to access, limiting admin access and applying the official fix will mitigate the risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-3r5c-2xxx-h872
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-58511"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- LOW
- Cvss Version
- 3.1
Threat ID: 6a600aa29c2644c7f8fdfcb5
Added to database: 07/22/2026, 00:11:14 UTC
Last enriched: 08/14/2026, 12:55:41 UTC
Last updated: 09/03/2026, 10:52:10 UTC
Views: 64
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.