ZeroHour

CVE-2026-27771

CVSS 3.0
8.2 high
EPSS
1%p71
Published
()
Modified
Description

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

Weakness
CWE-862
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news