Gitea Composer package source links use insufficient permission checks
56Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 8.2epss 1.4%
from disclosure to weapon0 days
Published on NVDJul 3
1st PoCMay 27
exploitation probability
1.4%top 30% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Affected products
Gitea · Gitea Open Source Git Serverpublic PoCs found — 2
githubgithub.com/portbuster1337/CVE-2026-27771★ 19githubgithub.com/HORKimhab/CVE-2026-27771★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.