Gitea.dev: Gitea: REST API exposes organization membership of private organizations to public (CVE-2026-58417)
A vulnerability in Gitea's REST API allows unauthorized users with an API token to confirm membership of users in private organizations. The endpoint /orgs/{org}/public_members/{username} returns a 204 status code when queried with valid parameters, leaking membership information that is otherwise hidden in the web interface. This disclosure affects Gitea versions prior to 1.27.0 and can reveal sensitive organizational membership data.
AI Analysis
Technical Summary
The vulnerability (CVE-2026-58417) exists in Gitea's REST API endpoint /orgs/{org}/public_members/{username}, which is intended to expose public members of an organization. However, in private organizations, this endpoint improperly reveals membership information by returning a 204 status code when queried with a valid username and organization name, even though the organization and its members are hidden in the web UI. This allows an authenticated user with an API token to confirm membership of users in private organizations. The issue affects Gitea versions prior to 1.27.0.
Potential Impact
This vulnerability leads to unauthorized disclosure of organization membership information for private organizations. Although the organization and its members are hidden in the web interface, the API endpoint leaks membership data to any user with an API token, potentially exposing sensitive information about organizational structure and membership.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict API token permissions and avoid exposing tokens to untrusted users. Monitor vendor channels for updates regarding a patch or official mitigation.
Gitea.dev: Gitea: REST API exposes organization membership of private organizations to public (CVE-2026-58417)
Description
A vulnerability in Gitea's REST API allows unauthorized users with an API token to confirm membership of users in private organizations. The endpoint /orgs/{org}/public_members/{username} returns a 204 status code when queried with valid parameters, leaking membership information that is otherwise hidden in the web interface. This disclosure affects Gitea versions prior to 1.27.0 and can reveal sensitive organizational membership data.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-58417) exists in Gitea's REST API endpoint /orgs/{org}/public_members/{username}, which is intended to expose public members of an organization. However, in private organizations, this endpoint improperly reveals membership information by returning a 204 status code when queried with a valid username and organization name, even though the organization and its members are hidden in the web UI. This allows an authenticated user with an API token to confirm membership of users in private organizations. The issue affects Gitea versions prior to 1.27.0.
Potential Impact
This vulnerability leads to unauthorized disclosure of organization membership information for private organizations. Although the organization and its members are hidden in the web interface, the API endpoint leaks membership data to any user with an API token, potentially exposing sensitive information about organizational structure and membership.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict API token permissions and avoid exposing tokens to untrusted users. Monitor vendor channels for updates regarding a patch or official mitigation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-jr5x-6h83-wrxf
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-58417"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a600ab79c2644c7f8fe24d6
Added to database: 07/22/2026, 00:11:35 UTC
Last enriched: 07/22/2026, 00:49:21 UTC
Last updated: 07/31/2026, 12:28:12 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.