VDB

GO-2026-4274

GO-2026-4274 PUBLISHED

Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists in code.gitea.io/gitea

Affected Products

VendorProductVersions
code.gitea.iogitea0, 0

Timeline

  • Jan 12, 2026 CVE Published
  • Mar 3, 2026 CVE Updated
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›