Junglewise Threat Intelligence

CVE-2026-50105: Gitea authorization bypass in RSS and Atom feed handlers

CVE-2026-50105 · Severity: medium · CVSS 4.3 · Published 2026-07-21

Technologies: code.gitea.io/gitea (Go), Gitea, gitea.dev (Go). Vendors: Go, Gitea.

Executive brief

Gitea is an open-source self-hosted software development platform. A vulnerability in its RSS and Atom feed handlers allows users with restricted access tokens to view private repository information that should be hidden from them. While this does not allow unauthorized users to access the platform, it means that limited-privilege tokens (such as those given to third-party tools) can leak private commit messages, release notes, and activity streams.

Technical details

Gitea's RSS/Atom feed handlers (including repo home, branch, release, and tag feeds) accept API tokens via Basic authentication but fail to call scope enforcement checks like 'CheckTokenScopes' or 'CheckRepoScopedToken'. This results in two confinement bypasses: tokens marked as 'public-only' can still access private repository feeds, and tokens with restricted scope categories (e.g., 'read:issue' only) can access repository commit and release metadata. The vulnerability allows the disclosure of commit SHAs, messages, author details, and release notes, though it does not expose raw file blobs. This issue is an incomplete fix of a previous security hardening effort that addressed similar leaks in download handlers. The vulnerability is patched in version 1.27.0.

Affected products

  • Gitea Gitea < 1.27.0

Timeline

  • 2026-07-13: disclosed
  • 2026-07-21: advisory
  • 2026-07-21: patched

References

Related threats