{"id":"CVE-2018-1000803","aliases":["GHSA-f5fj-7265-jxhj","GO-2022-0823"],"url":"https://o3.security/vulnerability/CVE-2018-1000803","summary":"Gitea Exposes Private Email Addresses","details":"Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appear to be exploitable via Watch a repository to receive email notifications. Emails received contain the other recipients even if they have the email set as private. This vulnerability appears to have been fixed in 1.5.1.","published":"2018-10-08T15:29:00.367Z","modified":"2026-08-07T14:54:00.132996Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/go-gitea/gitea","fixedVersion":"1.5.1"}],"fix":{"url":"https://github.com/go-gitea/gitea/pull/4664","label":"go-gitea/gitea#4664"},"references":[{"type":"FIX","url":"https://github.com/go-gitea/gitea/pull/4664"},{"type":"FIX","url":"https://github.com/go-gitea/gitea/pull/4664/files#diff-146e0c2b5bb1ea96c9fb73d509456e57"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:54:00.132996Z"}}