VDB
Sign up

GO-2026-6045

Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev

Quick fix

GO-2026-6045 — gitea.dev: upgrade to the fixed version with the command below.

go get gitea.dev@v1.27.0

Details

Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 in gitea.dev

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/gitea.dev
Introduced in: 0Fixed in: 1.27.0
Fixgo get gitea.dev@v1.27.0

References