CVE-2026-27771
HIGH
NVD
CVSS Score
8.2
Severity
HIGH
Published
Jul 03, 2026
Vendor
unknown
Description
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.