Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-56443: Gitea: Limited owners can access restricted repositories

CVE-2026-56443 · published 2 days ago
Summary

A vulnerability in Gitea allows limited owners of repositories to access restricted content using a public token. This affects API v1 packages and native package registries. To fix this, update to a patched version of Gitea.

What to do
  • Update code.gitea.io gitea to version 1.27.0.
Affected software
Ecosystem VendorProductAffected versions
go code.gitea.io gitea < 1.27.0
Fix: upgrade to 1.27.0
gitea gitea open source git server <= 1.26.4
Original advisory text
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
Severity
9.6 Critical
CVSS 3.1: 4.3 (GHSA)
Exploitation
EPSS <1%
Type
CWE-863Incorrect Authorization
Timeline
Published13 Aug 2026
Updated15 Aug 2026
First seen21 Jul 2026
Sources
CVE-2026-56443 · MITRE
Monitor software like this
Free during beta