Moderate severityNVD Advisory· Published Jul 3, 2026· Updated Jul 7, 2026
Gitea repository feeds bypass API token scope enforcement
CVE-2026-27761
Description
Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
code.gitea.io/giteaGo | < 1.26.3 | 1.26.3 |
Affected products
1Patches
Vulnerability mechanics
References
8- github.com/go-gitea/gitea/pull/38147ghsapatchWEB
- github.com/advisories/GHSA-3pww-vcvm-3gmjghsaADVISORY
- github.com/go-gitea/gitea/security/advisories/GHSA-3pww-vcvm-3gmjghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-27761ghsaADVISORY
- blog.gitea.com/release-of-1.26.3-and-1.26.4ghsaWEB
- blog.gitea.com/release-of-1.26.3-and-1.26.4/mitrerelease-notes
- github.com/go-gitea/gitea/commit/9e84deb969aff5c1115c2984e41250f28c78451fghsaWEB
- github.com/go-gitea/gitea/releases/tag/v1.26.3ghsarelease-notesWEB
News mentions
0No linked articles in our index yet.