Security Advisory

CVE-2026-20706

9.1
CRITICAL

Vulnerability Description

Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.
Published Date July 3, 2026
Official Source NIST NVD Advisory