Skip to content

Restricted users can read limited-visibility users’ SSH and GPG keys through the API

Moderate
bircni published GHSA-wwmh-7r9x-fg49 Aug 29, 2026

Package

Gitea

Affected versions

<= 1.27.2

Patched versions

1.27.3

Description

Summary

An authenticated account marked restricted can retrieve the SSH public keys and GPG keys of a user whose profile visibility is set to Limited, through GET /api/v1/users/{username}/keys and GET /api/v1/users/{username}/gpg_keys. The SSH response exposes key titles, public key material and fingerprints; the GPG response also exposes embedded email addresses. The equivalent web routes (/{user}.keys, /{user}.gpg) correctly deny the same viewer.

Details

The /users/{username} key route group is mounted without the profile-visibility guard used elsewhere, and the key and GPG-key list handlers resolve the target user and return key data without the visibility check that the web handler applies. Restricted users are meant to be treated like anonymous viewers for limited-visibility content.

Impact

Confidentiality only. A restricted viewer can enumerate and read the SSH and GPG keys, fingerprints and GPG-embedded email addresses of any Limited-visibility user on the instance. No organization membership, collaboration, admin right or special token scope is required.

Affected versions

Gitea <= 1.27.2.

Patches

Fixed in Gitea 1.27.3 (#39004, #39039).

Workarounds

None. Upgrade to 1.27.3.

Severity

Moderate

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVE ID

CVE-2026-68964

Weaknesses

No CWEs

Credits