← Back to browse · API

CVE-2026-27771

Severity
HIGH
CVSS
8.2
EPSS
0.43068
Risk score
47.87
CISA KEV
No
PoC
Yes
Published
2026-07-03
Modified
2026-07-07
First seen
2026-08-07
Aliases
EUVD-2026-41635, GHSA-8QW8-RQ86-9PC2
Products
Gitea:Gitea Open Source Git Server 0 ≤1.26.1, linux, suse
Sources
euvd EUVD-2026-41635
packetstorm e760ebd193aaec6c0d4acb9c|CVE-2026-27771

Description

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

References