---
id: CVE-2026-27761
title: >-
  Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed
  endpoints to bypass API access token scope checks, exposing private repository
  commit data to tokens without the required repository scope.
summary: >-
  Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed
  endpoints to bypass API access token scope checks, exposing private repository
  commit data to tokens without the required repository scope.
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-863
published: '2026-07-03'
updated: '2026-07-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-27761'
references:
  - url: 'https://blog.gitea.com/release-of-1.26.3-and-1.26.4/'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/pull/38147'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/releases/tag/v1.26.3'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/security/advisories/GHSA-3pww-vcvm-3gmj'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
tags:
  - nvd
epss: 0.00367
epssPercentile: 0.27911
ingestedAt: '2026-07-04T14:56:14.490Z'
---

## Overview

Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
