API Token Scope Bypass in Gitea by Gitea GmbH
CVE-2026-50105
Currently unrated
What is CVE-2026-50105?
This vulnerability allows unauthorized access to specific features by bypassing the expected API-token scoping rules in Gitea's RSS and Atom feed handlers. Due to an incomplete fix for a prior issue (#37698), attackers may exploit this flaw to manipulate feed handling in ways that compromise data security. It is crucial for users to update to the latest version of Gitea to mitigate potential risks associated with this vulnerability.
Affected Version(s)
Gitea Open Source Git Server 0 <= 1.26.4
