Impact
Gitea versions through 1.26.1 can include Composer package source-link information without enforcing the linked repository's read permissions [S1][S2]. Under the advisory conditions, a caller who can read a package may learn private or internal repository location metadata that they could not otherwise access. This is a missing-authorization issue (CWE-862), not proof that repository contents themselves were exposed [S3].
Root Cause
The affected Composer metadata response added a linked repository's source information without first checking the requester's repository access. Gitea 1.26.2 added that permission check and only includes the source link when the caller has the required repository access [S4][S5].
Covered by FixVibe
FixVibe's GitHub repo scans flag deployment files that pin a Gitea server image through 1.26.1, showing the file, line, pinned version and fixed version.
Fix
Upgrade every active Gitea server deployment to 1.26.2 or newer, preferably the latest supported release [S1][S5]. Update Docker, Compose, Kubernetes, Helm, GitOps, CI, and registry references that control the service, then rebuild or redeploy and verify the running version. Review Composer package visibility and linked-repository permissions through normal authorized administration after the upgrade.
