Summary
Gitea has insufficient permission checks for Composer package source links
Advisory details
CVE Description
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
Summary
A critical vulnerability has been discovered in Gitea. It was already reported via (security@gitea.io) from (dev@noscope.com), and submitted an encrypted report.
References
- https://github.com/advisories/GHSA-8qw8-rq86-9pc2
- https://github.com/go-gitea/gitea/security/advisories/GHSA-8qw8-rq86-9pc2
- https://nvd.nist.gov/vuln/detail/CVE-2026-27771
- https://github.com/go-gitea/gitea/pull/37610
- https://blog.gitea.com/release-of-1.26.2
- https://github.com/go-gitea/gitea/releases/tag/v1.26.2
Related vulnerabilities
All Supply chain →- CRITICALCVE-2026-73842
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
- HIGHCVE-2026-72795
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
- MEDIUMCVE-2026-72796
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
- MEDIUMCVE-2026-72797
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers
- HIGHCVE-2026-72798
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
- MEDIUMCVE-2026-72799
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers