CVE-2026-20706: Gitea Open Source Git Server
Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.
Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.
Affected products
- Gitea Gitea Open Source Git Server: up to and including 1.26.1
Published 2026-07-03. Last modified 2026-07-06.