← back
CVE-2026-27771highCWE-862

Gitea Composer package source links use insufficient permission checks

56Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 8.2epss 1.4%
from disclosure to weapon0 days
Published on NVDJul 3
1st PoCMay 27
exploitation probability
1.4%top 30% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.