Skip to content
Threat Feed
medium advisory

Information Disclosure Vulnerability in Gitea

A vulnerability in Gitea allows a remote, unauthenticated attacker to exploit an information disclosure flaw, potentially exposing sensitive repository or system data.

CVE search metadata

CVE search record: CVE-2024-52292. Severity: high. CVSS: 7.7. EPSS: 0.75%. KEV: no. Product: Gitea (< 1.22.6). Brief: Information Disclosure Vulnerability in Gitea. Brief link: https://feed.craftedsignal.io/briefs/2026-09-gitea-info-disclosure/

A security vulnerability exists in Gitea versions prior to 1.22.6, which permits a remote, unauthenticated attacker to perform information disclosure. This flaw enables unauthorized access to repository data or internal system information that should otherwise be restricted. Defenders should prioritize patching to Gitea version 1.22.6 or later to mitigate the risk of data leakage.

Impact

Successful exploitation of this vulnerability allows unauthorized actors to access sensitive internal data, potentially leading to the exposure of proprietary source code, credentials, or metadata stored within the Gitea instance. The scope of impact affects any organization hosting Gitea instances vulnerable to this specific information disclosure flaw.

Recommendation

  • Patch Gitea to version 1.22.6 or later immediately.
  • Audit access logs for unusual patterns of unauthenticated requests targeting repository metadata or configuration endpoints.

Mitigations

Upgrade Gitea to version 1.22.6 or later

immediate IT Operations

CVE-2024-52292