CVE-2026-27771
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
- Affected products
- Gitea
- Fix
- Available
- CVSS 3.0
- 8.2 HIGH
- EPSS
- 1.4% (70th percentile)
- Weakness
- CWE-862
- NVD status
- Deferred
- Published
- 2026-07-03
CVE-2026-27771 at NVD
3 known exploits for CVE-2026-27771
Proof-of-concept code and exploit modules indexed by Sploitus