{"id":"CVE-2026-58440","aliases":["GHSA-66m4-5jjr-2rg5"],"title":"Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content","summary":"Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content","severity":"medium","cvss":6.8,"cwe":["CWE-863"],"vendor":"gitea.dev","product":"gitea.dev","ecosystem":"go","affected":["gitea.dev < 1.27.0"],"patched":["gitea.dev 1.27.0"],"published":"2026-07-21","updated":"2026-07-21","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-66m4-5jjr-2rg5","references":[{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-66m4-5jjr-2rg5"},{"url":"https://github.com/go-gitea/gitea/pull/38406"},{"url":"https://github.com/go-gitea/gitea/pull/38426"},{"url":"https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d31"},{"url":"https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7bf"},{"url":"https://github.com/go-gitea/gitea/releases/tag/v1.27.0"},{"url":"https://github.com/advisories/GHSA-66m4-5jjr-2rg5"}],"tags":["ghsa","go"],"ingestedAt":"2026-07-21T20:54:27.562Z","epss":0.00278,"epssPercentile":0.205,"slug":"CVE-2026-58440","body":"## Overview\n\n## Affected product\nGitea — `services/repository/collaboration.go` (`DeleteCollaboration`) + webhook delivery\n\n## Summary\nWhen a collaborator with admin permission on a private repo creates a webhook, that webhook keeps firing\nafter the collaborator's access is revoked. Gitea's revocation cleanup `DeleteCollaboration` removes the\ncollaboration record, recalculates accesses, drops watches, and unassigns issues — but it does **not**\nremove or disable webhooks the user created, and webhook delivery never re-checks whether the creator still\nhas repo access. The former collaborator therefore receives the full payload (issue/comment bodies, commit\ndata) of all future repository events at their controlled endpoint, indefinitely and invisibly.\n\n## Affected code\n- `services/repository/collaboration.go` → `DeleteCollaboration()` — cleans watches/assignees only; no\n  webhook cleanup.\n- Webhook delivery path — fires on repo events without re-validating the creator's current access.\n\n## Steps to reproduce\nUsing the provided reproduction materials:\n1. Attacker (admin collaborator) creates a webhook → revoke access.\n2. Control: `GET /api/v1/repos/admin/wh-repo` (attacker) → **404**.\n3. `GET .../hooks` → webhook still `active=true`.\n4. Admin creates a new issue **after** revocation → the catcher receives `action:\"opened\"`,\n   `issue.title:\"CRITICAL SECRET: …\"`, `issue.body` (sentinel private key), `repository.private:true`.\n(Runtime-confirmed on `gitea/gitea:1.25.4`. Catcher is an internal sentinel listener; the payload is a\nplanted sentinel, not real data; nothing is sent to any external/metadata endpoint.)\n\n## Impact\nAuthenticated former admin-collaborator → ongoing real-time exfiltration of private content created after\nrevocation; invisible to the owner; scope crosses from the application boundary to data the user should no\nlonger access.\n\n## Suggested remediation\n1. On revocation, delete/disable webhooks created by the removed collaborator (or hand them to the owner).\n2. Re-validate the creator's current repo access before each webhook delivery.\n3. At minimum, warn admins on revocation if the user created webhooks.\n\n## Credit\nReported as part of an incomplete-patch / authorization-residue measurement study (responsible disclosure).\n\n## Affected packages\n\n- `gitea.dev < 1.27.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `gitea.dev 1.27.0`","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}