← Back

CVE-2026-27761

nvd nist
Published: Jul 3, 2026Modified: Jul 7, 2026Deferred

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2 (Secondary)

Description

Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.

References (5)

Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2

Timeline

No history available yet.