GHSA-qf2f-qh6p-7v89: Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`
Summary
CVE-2026-20800 fixed private-info leakage to revoked users only for the notification endpoint. Two
sibling endpoints that return data keyed on the caller's own relationship still do not re-check repo
access at output time:
- GET /api/v1/user/starred — getStarredRepos() computes a per-repo permission but still lists every
starred repo (no filtering), so the full repo object (full_name, private, clone_url, ssh_url)
of a now-inaccessible private repo is returned.
- GET /api/v1/user/times — ListMyTrackedTimes() queries by UserID only and LoadAttributes brings
in the issue (title, state), leaking private issue titles after revocation.
Steps to reproduce
Using the provided reproduction materials, as a revoked user:
1. Control: GET /api/v1/repos/admin/starred-test → 404.
2. GET /api/v1/user/starred → leaks admin/starred-test, private:true, clone_url.
3. GET /api/v1/user/times → leaks issue.title = "SECRET: …", state.
(Runtime-confirmed on gitea/gitea:1.25.4. Oracle = planted sentinel title; no real secret exfiltrated.)
Impact
A former collaborator can enumerate private repos they starred and read private issue titles they logged
time on, indefinitely after access revocation. Metadata only (no repo content / comment bodies). Low.
Suggested remediation
1. getStarredRepos: drop (or minimally redact) repos where permission.HasAnyUnitAccessOrPublicAccess()
is false for the caller.
2. ListMyTrackedTimes: filter tracked-time entries by current repo access.
3. Optionally clear a user's stars / time entries for a private repo on revocation.
Credit
Reported as part of an incomplete-patch measurement study (responsible disclosure).
Details
Original advisory: https://github.com/advisories/GHSA-qf2f-qh6p-7v89
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-59766 | coverage & exploitation status | NVD · CVE.org |
More from GitHub Security Advisories
- mediumGHSA-jr6p-8pjj-mfx6: Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators s…2026-07-31
- mediumGHSA-68cj-mvg9-rgm2: Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing…2026-07-31
- mediumGHSA-ff84-5f28-78qj: re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex`…2026-07-31
- mediumGHSA-6hxr-mr5r-9836: re2: Global `String.prototype.match` with an empty-matchable pattern never advances → inf…2026-07-31
- mediumGHSA-x83g-979r-f5fh: Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII2026-07-31