Threats Tagged 'cve-2026-59766'
View all threats tagged with 'cve-2026-59766'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-59766'
Click on any threat for detailed analysis and mitigation recommendations
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` (CVE-2026-59766)CVE-2026-59766 0 Gitea versions prior to 1.27.0 contain a vulnerability where revoked users can still access metadata of private repositories and private issue titles via two API endpoints: /api/v1/user/starred and /api/v1/user/times. This occurs because these endpoints do not properly re-check repository access permissions at output time, allowing former collaborators to enumerate private repos they had starred and read private issue titles indefinitely after access revocation. The leaked information is limited to metadata and does not include repository content or comment bodies. Join the discussion | GCVE Database | 07/21/2026, 20:13:03 UTC Added: 07/22/2026, 00:11:41 UTC |
Showing 1 to 1 of 1 result