Ghostwire

CVE-2026-27771: Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which...

HIGH CVSS 0.0

Published: July 3, 2026 | Last Modified: July 3, 2026

Description

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (3 articles)

References