Description
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
Published: 2026-07-03
Score: 8.2 High
EPSS: 43.1% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information. Based on the description, this appears to be a missing authorization check (CWE-862).

Affected Systems

The affected product is the Gitea Open Source Git Server. Versions 1.26.1 and any earlier releases are impacted. Users operating these versions should be aware that source links can be accessed without proper permission checks.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. An EPSS score of 41% indicates a moderate to high likelihood of exploitation. The CVE is not listed in the CISA KEV catalog, meaning no known active exploits have been reported. Based on the description, it is inferred that an attacker could by accessing Composer package source links without proper permission checks.

Generated by OpenCVE AI on July 24, 2026 at 10:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Gitea to version 1.26.2 or later to apply the vendor patch that includes the permission check.
  • If an upgrade cannot be applied immediately, restrict web API access to Composer package source links by configuring firewall rules or adjusting Gitea API permissions to allow access only to users with explicit repository read permissions.
  • Conduct a review and audit of repository access controls to ensure that no publicly exposed APIs inadvertently provide internal package source URLs, and apply tighter role‑based access control where needed.

Generated by OpenCVE AI on July 24, 2026 at 10:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8qw8-rq86-9pc2 Gitea has insufficient permission checks for Composer package source links
History

Tue, 07 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Gitea
Gitea gitea Open Source Git Server
Vendors & Products Gitea
Gitea gitea Open Source Git Server

Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
Title Gitea Composer package source links use insufficient permission checks
Weaknesses CWE-862
References
Metrics cvssV3_0

{'score': 8.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Gitea Gitea Open Source Git Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Gitea

Published:

Updated: 2026-07-07T16:58:45.839Z

Reserved: 2026-03-03T03:25:50.291Z

Link: CVE-2026-27771

cve-icon Vulnrichment

Updated: 2026-07-07T14:32:54.442Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T10:45:03Z

Weaknesses