Junglewise Threat Intelligence

CVE-2026-20883: GO-2026-4368 - Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea

CVE-2026-20883 · Severity: medium · CVSS 4 · Published 2026-02-02

Technologies: code.gitea.io/gitea (Go), github.com/go-gitea/gitea (Go). Vendors: Go.

Executive brief

Gitea improperly exposes issue titles and repository names through previously started stopwatches in code.gitea.io/gitea

Affected products

  • Go code.gitea.io/gitea
  • Go github.com/go-gitea/gitea

Related threats