FixVibe

high

Gitea Insufficient Permission Checks for Composer Package Source Links (CVE-2026-27771)

Gitea versions through 1.26.1 can expose Composer package source-link information when package and linked-repository permissions differ. FixVibe GitHub repo scans flag pinned Gitea server images in the affected range.

CVE-2026-27771GHSA-8qw8-rq86-9pc2GHSA-8qw8-rq86-9pc2CWE-862

Impact

Gitea versions through 1.26.1 can include Composer package source-link information without enforcing the linked repository's read permissions [S1][S2]. Under the advisory conditions, a caller who can read a package may learn private or internal repository location metadata that they could not otherwise access. This is a missing-authorization issue (CWE-862), not proof that repository contents themselves were exposed [S3].

Root Cause

The affected Composer metadata response added a linked repository's source information without first checking the requester's repository access. Gitea 1.26.2 added that permission check and only includes the source link when the caller has the required repository access [S4][S5].

Covered by FixVibe

FixVibe's GitHub repo scans flag deployment files that pin a Gitea server image through 1.26.1, showing the file, line, pinned version and fixed version.

Fix

Upgrade every active Gitea server deployment to 1.26.2 or newer, preferably the latest supported release [S1][S5]. Update Docker, Compose, Kubernetes, Helm, GitOps, CI, and registry references that control the service, then rebuild or redeploy and verify the running version. Review Composer package visibility and linked-repository permissions through normal authorized administration after the upgrade.