CVE-2026-28740: Gitea Open Source Git Server
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.
Affected products
- Gitea Gitea Open Source Git Server: up to and including 1.26.2
Published 2026-07-03. Last modified 2026-07-07.