Incorrect authorization in Gitea - CVE-2026-56443

 

Incorrect authorization in Gitea - CVE-2026-56443

Published: July 14, 2026


Vulnerability identifier: #VU137432
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-56443
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose limited-visibility repository and package content.

The vulnerability exists due to incorrect authorization in public-only personal access token scope checks for repository and package access controls when handling requests for resources owned by limited-visibility users or organizations. A remote user can use a public-only token to access repository and package endpoints to disclose limited-visibility repository and package content.

The issue affects repository and package scope categories, while sibling user and organization scope checks correctly reject the same access pattern.


Affected software

Gitea

How to mitigate CVE-2026-56443

Install security update from vendor's website.

Gitea - update to 1.27.0

External References

Related Security Bulletins