High severity8.2NVD Advisory· Published Jul 3, 2026· Updated Jul 7, 2026
CVE-2026-27771
CVE-2026-27771
Description
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
code.gitea.io/giteaGo | < 1.26.2 | 1.26.2 |
Affected products
2- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-8qw8-rq86-9pc2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-27771ghsaADVISORY
- blog.gitea.com/release-of-1.26.2ghsaWEB
- github.com/go-gitea/gitea/pull/37610nvdWEB
- github.com/go-gitea/gitea/releases/tag/v1.26.2nvdWEB
- github.com/go-gitea/gitea/security/advisories/GHSA-8qw8-rq86-9pc2nvdWEB
- blog.gitea.com/release-of-1.26.2/nvd
News mentions
2- Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode MarkupThe Hacker News · Aug 5, 2026
- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS HijacksThe Hacker News · Aug 3, 2026