Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.3
CVE-2026-20706: Gitea: Private repositories exposed through archive download
GHSA-cr4g-f395-h25h
CVE-2026-20706
GHSA-cr4g-f395-h25h
CVE-2026-20706
Summary
A vulnerability in Gitea allows users with personal access tokens of any scope to download private repository archives. This affects users who have created such tokens, potentially exposing sensitive information. To mitigate this, ensure that personal access tokens are created with the correct repository scope.
What to do
- Update code.gitea.io gitea to version 1.26.2.
- Update gitea code.gitea.io/gitea to version 1.26.2.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| go | code.gitea.io | gitea |
<= 1.26.1 Fix: upgrade to 1.26.2
|
| Go | gitea | code.gitea.io/gitea |
< 1.26.2 Fix: upgrade to 1.26.2
|
| – | gitea | gitea open source git server | <= 1.26.1 |
Original title
Gitea repository archive downloads bypass token scope checks
Original description
Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.
ghsa CVSS4.0
5.3
Vulnerability type
CWE-863
Incorrect Authorization
CWE-284
Improper Access Control
- https://github.com/go-gitea/gitea/security/advisories/GHSA-cr4g-f395-h25h
- https://github.com/advisories/GHSA-cr4g-f395-h25h
- https://github.com/go-gitea/gitea Product
- https://github.com/go-gitea/gitea/pull/37735 patch
- https://github.com/go-gitea/gitea/releases/tag/v1.26.2 release-notes
- https://blog.gitea.com/release-of-1.26.2/ release-notes
Published: 3 Jul 2026 · Updated: 23 Jul 2026 · First seen: 17 Jun 2026