CVE-2026-27761: Gitea Open Source Git Server
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.
Affected products
- Gitea Gitea Open Source Git Server: up to and including 1.26.2
Published 2026-07-03. Last modified 2026-07-07.