Skip to content

Known CVE

Gitea Container Registry - Unauthorized Private Image Access

Gitea < 1.26.2 allows unauthenticated remote attackers to pull private container images.The /v2/token endpoint grants anonymous ghost tokens (UserID:-1) with no scope restriction.The ReqContainerAccess middleware does not check package owner visibility, so ghost users can enumerate all container repositories via /_catalog and pull any private image layer.

CVE-2026-27771

High2026CVSS 7.5CWE-862

cve2026 · gitea · container · registry · auth-bypass · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website