Junglewise Threat Intelligence

CVE-2026-28744: Gitea repository token scope bypass in Git smart HTTP requests

CVE-2026-28744 · Severity: high · CVSS 8.1 · Published 2026-07-03

Technologies: code.gitea.io/gitea (Go), Gitea. Vendors: Go, Gitea.

Executive brief

Gitea, a popular self-hosted Git service, contains a security flaw where certain authentication tokens do not properly enforce restricted permissions. An attacker with a valid but limited-access token could bypass intended security boundaries to read from or write to private code repositories they should not have access to. This could lead to the theft of proprietary source code or unauthorized modifications to software projects.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Gitea's Git smart HTTP request handling. The 'CheckRepoScopedToken' function was designed to enforce repository-scoped access permissions but incorrectly returned early if the request did not use HTTP Basic authentication. Consequently, when a Personal Access Token (PAT) or OAuth2 token is presented using 'Authorization: Bearer' instead of Basic auth, the scope checks are bypassed. This allows an authenticated user with a restricted token to perform unauthorized git-upload-pack (clone/fetch) or git-receive-pack (push) operations against private repositories. The issue is resolved in version 1.26.2 by ensuring scope enforcement applies to all API-token-authenticated requests.

Affected products

  • Gitea Gitea Open Source Git Server <= 1.26.1

Timeline

  • 2026-05-08: patched: Fix merged into main branch
  • 2026-05-20: advisory: Gitea 1.26.2 released with security fix
  • 2026-07-03: disclosed: CVE-2026-28744 published to NVD

References

Related threats