Beveiligingsadvies

CVE-2026-27761

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-03 20:19:36
Laatst bijgewerkt 2026-07-07 16:58:51
Toegewezen door Gitea
CVSS-score 4.3
Status PUBLISHED

Beschrijving

Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.