Personal Access Token Scope Enforcement Bypass in Gitea
CVE-2026-58444

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-58444?

A vulnerability in Gitea allows unauthorized access to private repository contents through a bypass of personal access token scope enforcement. This issue can occur when a user accesses the repository homepage using a GET request, which may disclose sensitive repository data to users who should not have access. To mitigate this risk, users are advised to update to the latest version of Gitea and review their access token configurations.

Affected Version(s)

Gitea Open Source Git Server 0 < 1.27.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

StarPlatinu
.