Junglewise Threat Intelligence

CVE-2026-27761: Gitea authorization bypass in RSS and Atom feed endpoints

CVE-2026-27761 · Severity: medium · CVSS 4.3 · Published 2026-07-03

Technologies: code.gitea.io/gitea (Go), Gitea. Vendors: Go, Gitea.

Executive brief

Gitea, a popular self-hosted Git service, contains a vulnerability where restricted access tokens can bypass security boundaries to view private code history. Specifically, a token intended only for managing issues or other non-code tasks can be used to read commit messages, author details, and internal context from private repositories via RSS/Atom feeds. This could lead to the exposure of sensitive information or secrets accidentally included in commit descriptions.

Technical details

An authorization bypass exists in Gitea's RSS/Atom feed handlers because they fail to call the `checkDownloadTokenScope()` function. While these endpoints correctly authenticate users via Personal Access Tokens (PATs), the middleware only verifies the user's general access rights and ignores the specific scope restrictions of the token (e.g., a token limited to `read:issue` can still access code feeds). An attacker with a valid, low-privileged PAT can exfiltrate commit SHAs, full commit messages, and committer metadata from any private repository the token owner has access to. The vulnerability affects multiple handlers including `RenderBranchFeedRSS/Atom`, `ShowFileFeed`, and repository activity feeds. This issue is addressed in Gitea version 1.26.3.

Affected products

  • Gitea Gitea <= 1.26.2

Timeline

  • 2026-06-13: other: Confirmed present at main HEAD
  • 2026-06-21: patched: Gitea version 1.26.3 released
  • 2026-07-03: advisory: NVD publication date
  • 2026-07-21: disclosed: GitHub Advisory published

References

Related threats