Feed/CVE-2026-27771
CVE-2026-27771HIGHCVSS 8.2

CVE-2026-27771

Published Jul 3, 2026·Updated Jul 17, 2026

NVD Description

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

Affected Packages (1)

code.gitea.io/giteaGO
Fixed in = 1.26.1

Public Exploits & PoCs2 found

Community Discussion

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free