Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

CVE-2026-20706: Gitea: Private repositories exposed through archive download

GHSA-cr4g-f395-h25h CVE-2026-20706 GHSA-cr4g-f395-h25h CVE-2026-20706
Summary

A vulnerability in Gitea allows users with personal access tokens of any scope to download private repository archives. This affects users who have created such tokens, potentially exposing sensitive information. To mitigate this, ensure that personal access tokens are created with the correct repository scope.

What to do
  • Update code.gitea.io gitea to version 1.26.2.
  • Update gitea code.gitea.io/gitea to version 1.26.2.
Affected software
Ecosystem VendorProductAffected versions
go code.gitea.io gitea <= 1.26.1
Fix: upgrade to 1.26.2
Go gitea code.gitea.io/gitea < 1.26.2
Fix: upgrade to 1.26.2
– gitea gitea open source git server <= 1.26.1
Original title
Gitea repository archive downloads bypass token scope checks
Original description
Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.
ghsa CVSS4.0 5.3
Vulnerability type
CWE-863 Incorrect Authorization
CWE-284 Improper Access Control
Published: 3 Jul 2026 · Updated: 23 Jul 2026 · First seen: 17 Jun 2026