CVE-2026-58440
Description
AI Translation Available
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)
284
Improper Access Control
IncompleteCommon Consequences
Security Scopes Affected:
Other
Potential Impacts:
Varies By Context
Applicable Platforms
Technologies:
Not Technology-Specific, ICS/OT, Web Based
https://blog.gitea.com/gitea-1.27.0-is-released/
https://github.com/go-gitea/gitea/releases/tag/v1.27.0
https://github.com/go-gitea/gitea/security/advisories/GHSA-66m4-5jjr-2rg5