Ghostwire

CVE-2026-56443: Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after...

MEDIUM CVSS 4.3 Exploit Available

Published: July 21, 2026 | Last Modified: July 21, 2026

Description

Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References