GHSA-8qw8-rq86-9pc2

Suggest an improvement
Source
https://github.com/advisories/GHSA-8qw8-rq86-9pc2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-8qw8-rq86-9pc2/GHSA-8qw8-rq86-9pc2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8qw8-rq86-9pc2
Aliases
Published
2026-07-17T19:04:37Z
Modified
2026-07-22T21:11:25Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
Gitea has insufficient permission checks for Composer package source links
Details

CVE Description

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

Summary

A critical vulnerability has been discovered in Gitea. It was already reported via (security@gitea.io) from (dev@noscope.com), and submitted an encrypted report.

Database specific
{
    "cwe_ids":  [
        "CWE-862"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-17T19:04:37Z",
    "nvd_published_at":  "2026-07-03T21:16:59Z",
    "severity":  "HIGH"
}
References

Affected packages

Go / code.gitea.io/gitea

Package

Name
code.gitea.io/gitea
View open source insights on deps.dev
Purl
pkg:golang/code.gitea.io/gitea

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.26.2

Database specific

last_known_affected_version_range
"<= 1.26.1"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-8qw8-rq86-9pc2/GHSA-8qw8-rq86-9pc2.json"