Known CVE
Gitea Container Registry - Unauthorized Private Image Access
Gitea < 1.26.2 allows unauthenticated remote attackers to pull private container images.The /v2/token endpoint grants anonymous ghost tokens (UserID:-1) with no scope restriction.The ReqContainerAccess middleware does not check package owner visibility, so ghost users can enumerate all container repositories via /_catalog and pull any private image layer.
CVE-2026-27771
High2026CVSS 7.5CWE-862
cve2026 · gitea · container · registry · auth-bypass · unauth
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website