Skip to content

Package registry: restricted users can read packages of limited-visibility users (authorization bypass)

Moderate
bircni published GHSA-px3q-x2mm-55wg Aug 29, 2026

Package

gomod code.gitea.io/gitea (Go)

Affected versions

<= 1.27.2

Patched versions

1.27.3

Description

Summary

The package-registry access check grants read access to a package owned by a Limited-visibility user to any non-ghost logged-in user, without excluding restricted accounts. A restricted account can therefore enumerate and download the entire package registry (for example Docker, npm, PyPI) of any Limited-visibility user.

Details

The user-owner branch of determineAccessMode omits the restricted-user check that the organization-owner branch and the repository permission model apply.

Impact

Authorization boundary / confidentiality. A restricted account can read package content of Limited-visibility users that it should not be able to see.

Affected versions

Gitea <= 1.27.2.

Patches

Fixed in Gitea 1.27.3 (#39043, #39058).

Workarounds

None. Upgrade to 1.27.3.

Severity

Moderate

CVE ID

CVE-2026-66849

Weaknesses

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. Learn more on MITRE.

Credits