Executive brief
Gitea, a popular self-hosted Git service, contains a vulnerability where restricted access tokens can bypass security boundaries to view private code history. Specifically, a token intended only for managing issues or other non-code tasks can be used to read commit messages, author details, and internal context from private repositories via RSS/Atom feeds. This could lead to the exposure of sensitive information or secrets accidentally included in commit descriptions.
Technical details
An authorization bypass exists in Gitea's RSS/Atom feed handlers because they fail to call the `checkDownloadTokenScope()` function. While these endpoints correctly authenticate users via Personal Access Tokens (PATs), the middleware only verifies the user's general access rights and ignores the specific scope restrictions of the token (e.g., a token limited to `read:issue` can still access code feeds). An attacker with a valid, low-privileged PAT can exfiltrate commit SHAs, full commit messages, and committer metadata from any private repository the token owner has access to. The vulnerability affects multiple handlers including `RenderBranchFeedRSS/Atom`, `ShowFileFeed`, and repository activity feeds. This issue is addressed in Gitea version 1.26.3.
Affected products
- Gitea Gitea <= 1.26.2
Timeline
- 2026-06-13: other: Confirmed present at main HEAD
- 2026-06-21: patched: Gitea version 1.26.3 released
- 2026-07-03: advisory: NVD publication date
- 2026-07-21: disclosed: GitHub Advisory published