VDB
KO

GO-2026-6071

Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev

Quick fix

GO-2026-6071 — gitea.dev: upgrade to the fixed version with the command below.

go get gitea.dev@v1.27.0

Details

Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times` in gitea.dev

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / gitea.dev
Introduced in: 0 Fixed in: 1.27.0
Fix go get gitea.dev@v1.27.0

References