CVE-2026-27771: Gitea Open Source Git Server

High severity, CVSS 8.2. EPSS: 1.4% chance of exploitation in the next 30 days.

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

Affected products

  • Gitea Gitea Open Source Git Server: up to and including 1.26.1

Published 2026-07-03. Last modified 2026-07-07.