CVE-2026-96589
Description
When a private repository is transferred to a user who lacks access, Gitea grants that recipient temporary read access as a collaborator so they can review the repository. Rejecting or cancelling the transfer did not revoke this collaboration, so the named recipient kept persistent read access to the private repository, including its code, issues, pull requests and wiki, and could clone it. The repository owner was not notified. Transfer-granted access is now removed while collaborations that existed before the transfer are preserved.
Is your site exposed to CVE-2026-96589?
Run a free security scan — no signup, results in seconds.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-96589? +
How do I check if I'm vulnerable to CVE-2026-96589? +
Related Vulnerabilities
JWK Set (JSON Web Key Set) is a JWK and JWK Set Go implementation. Prior to 0.6.0, the project's provided …
Use of released resource in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the …
Use of released resource in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the …
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be …
Use of released resource in FontAccess in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the …
Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from …