Vulnerabilidad · Publicado 03/07/2026 · Actualizado 01/08/2026
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
Score: 8.2/10 — Severidad: HIGH — Estado NIST: Deferred
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CWE-862
Publicado en NIST NVD.