CVE-2026-27771
HIGH 8.2EPSS 1.4%
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
- CVSS v3.0
- 8.2 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N - CVSS v3.0
- 8.2 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N - EPSS
- 1.39% chance of exploitation in the next 30 days, 70th percentile
- Nuclei
- high · CWE-862
- Published
- 2026-07-03
- Updated
- 2026-07-07
Proof-of-concept exploits (2)
- portbuster1337/CVE-2026-2777119★ · 2026-05-27
- HORKimhab/CVE-2026-277710★ · 2026-05-27