Exposure of Sensitive Information Through Metadata Affecting github.com/go-gitea/gitea/services/context package, versions <1.27.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.26% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMGOGITEAGITEASERVICESCONTEXT-18678067
  • published12 Aug 2026
  • disclosed21 Jul 2026
  • creditGhost 💀

Introduced: 21 Jul 2026

CVE-2026-58507  (opens in a new tab)
CWE-1230  (opens in a new tab)

How to fix?

Upgrade github.com/go-gitea/gitea/services/context to version 1.27.0 or higher.

Overview

Affected versions of this package are vulnerable to Exposure of Sensitive Information Through Metadata via the EarlyResponseForGoGetMeta function. An attacker can obtain sensitive repository metadata, such as the existence of private repositories, their clone URLs, and default branch names, by sending unauthenticated HTTP requests with the ?go-get=1 query parameter.

CVSS Base Scores

version 4.0
version 3.1