API Token Scope Bypass in Gitea by Gitea GmbH
CVE-2026-50105

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-50105?

This vulnerability allows unauthorized access to specific features by bypassing the expected API-token scoping rules in Gitea's RSS and Atom feed handlers. Due to an incomplete fix for a prior issue (#37698), attackers may exploit this flaw to manipulate feed handling in ways that compromise data security. It is crucial for users to update to the latest version of Gitea to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CassianStarck
.