CVE-2026-28744: Gitea Open Source Git Server
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.
Affected products
- Gitea Gitea Open Source Git Server: up to and including 1.26.1
Published 2026-07-03. Last modified 2026-07-06.