← back
CVE-2026-28744highCWE-863

Gitea Git smart HTTP bypasses repository token scopes for bearer tokens

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.1epss 0.3%
exploitation probability
0.3%top 73% of all CVEs
observed exploitation
nono source reports it
Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N