SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityDeferred

CVE-2026-27771

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

HIGH 8.2EPSS 1.39%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.39%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

CVSS 3.0
8.2 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
EPSS
1.39% probability · 71th percentile
CISA KEV
Not listed
Weakness
CWE-862
Source
88ee5874-cf24-4952-aea0-31affedb7ff2

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.