Description
Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.
Related CPE's
Could not find any relations
References
Weaknesses
88ee5874-cf24-4952-aea0-31affedb7ff2
Secondary
CWE-863
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
4.3 · Medium
Information
Source identifier
88ee5874-cf24-4952-aea0-31affedb7ff2
Vulnerability status
Deferred
Published
2026-07-03T21:16:58.937Z
3 months agoLast modified
2026-07-07T18:16:37.887Z
3 months ago