PoC Index

CVE-2026-27771

HIGH 8.2EPSS 1.4%

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

CVSS v3.0
8.2 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVSS v3.0
8.2 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
EPSS
1.39% chance of exploitation in the next 30 days, 70th percentile
Nuclei
high · CWE-862
Published
2026-07-03
Updated
2026-07-07

Proof-of-concept exploits (2)

Nuclei templates (1)

References

Related