Personal Access Token Scope Enforcement Bypass in Gitea
CVE-2026-58444
Currently unrated
What is CVE-2026-58444?
A vulnerability in Gitea allows unauthorized access to private repository contents through a bypass of personal access token scope enforcement. This issue can occur when a user accesses the repository homepage using a GET request, which may disclose sensitive repository data to users who should not have access. To mitigate this risk, users are advised to update to the latest version of Gitea and review their access token configurations.
Affected Version(s)
Gitea Open Source Git Server 0 < 1.27.0
