Ghostwire

CVE-2026-27761: Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope...

MEDIUM CVSS 0.0

Published: July 3, 2026 | Last Modified: July 3, 2026

Description

Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References