Security Advisory
CVE-2026-28744
8.1
HIGH
Vulnerability Description
Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.
Published Date
July 3, 2026
Official Source
NIST NVD Advisory