Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-56443: Gitea: Limited owners can access restricted repositories
CVE-2026-56443 · published 2 days ago
Summary
A vulnerability in Gitea allows limited owners of repositories to access restricted content using a public token. This affects API v1 packages and native package registries. To fix this, update to a patched version of Gitea.
What to do
- Update code.gitea.io gitea to version 1.27.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| go | code.gitea.io | gitea |
< 1.27.0 Fix: upgrade to 1.27.0
|
| – | gitea | gitea open source git server | <= 1.26.4 |
Original advisory text
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
Severity
9.6
Critical
CVSS 3.1: 4.3 (GHSA)
Exploitation
EPSS <1%
Type
CWE-863Incorrect Authorization
Timeline
Published13 Aug 2026
Updated15 Aug 2026
First seen21 Jul 2026
Monitor software like this
Free during beta