CVE-2026-27771: Gitea Composer package source links use insufficient permission checks
CVE Description Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
Summary A critical vulnerability has been discovered in Gitea. It was already reported via (security@gitea.io) from (dev@noscope.com), and submitted an encrypted report.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/code.gitea.io/giteato a version that resolves this vulnerability.Fixed in 1.26.2 - Upgrade
Upgrade
giteato a version that resolves this vulnerability.Fixed in 1.26.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27771?
CVE-2026-27771 has a severity score of 8.2, indicating a high severity vulnerability.
How do I fix CVE-2026-27771?
To fix CVE-2026-27771, upgrade Gitea to version 1.26.2 or later.
What information is exposed by CVE-2026-27771?
CVE-2026-27771 exposes private or internal package source information due to insufficient permission checks.
Which versions of Gitea are affected by CVE-2026-27771?
Gitea versions up to and including 1.26.1 are affected by CVE-2026-27771.
What types of vulnerabilities does CVE-2026-27771 represent?
CVE-2026-27771 represents a security vulnerability related to insufficient permission checks for Composer package source links.