VYPR
Moderate severityNVD Advisory· Published Jul 3, 2026· Updated Jul 7, 2026

Gitea repository feeds bypass API token scope enforcement

CVE-2026-27761

Description

Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
code.gitea.io/giteaGo
< 1.26.31.26.3

Affected products

1

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.