---
id: CVE-2026-97626
title: >-
  Requesting a user or organization profile page (`GET /{username}`) with an
  `Accept: application/rss+xml` or `Accept: application/atom+xml` header
  returned the owner's activity feed without the visibility check that the
  profile page and t…
summary: >-
  Requesting a user or organization profile page (`GET /{username}`) with an
  `Accept: application/rss+xml` or `Accept: application/atom+xml` header
  returned the owner's activity feed without the visibility check that the
  profile page and t…
severity: none
cwe:
  - CWE-200
  - CWE-863
vendor: Gitea
product: gitea.dev
affected:
  - gitea.dev <= 28.0.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:17:08.047'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97626'
references:
  - url: 'https://blog.gitea.com/release-of-28.1.0/'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/pull/39501'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/pull/39507'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/releases/tag/v28.1.0'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/security/advisories/GHSA-hf55-9cwq-2x64'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T22:23:15.973Z'
---

## Overview

Requesting a user or organization profile page (`GET /{username}`) with an `Accept: application/rss+xml` or `Accept: application/atom+xml` header returned the owner's activity feed without the visibility check that the profile page and the `.rss` and `.atom` routes apply. Anonymous users, restricted users and non-members could confirm the existence of limited or private users and private organizations and read their profile details and public activity, also when `[other] ENABLE_FEED` was disabled. Activity in private repositories was not included.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
