CVE-2026-58444

Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents


We have discovered 777 live websites that are affected by CVE-2026-58444.

Run a Free Instant Scan




Affected Software

Product  Gitea
Category Dev Tools
Vulnerable Domains777 live websites (100% of Gitea install base)
Vulnerable Versions
  • from 0 through 1.27
Vulnerable Versions Count66 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Aug 13, 2026
  • Updated - Aug 14, 2026

Credits

  • StarPlatinu (reporter)

Website Distribution by Country

Number of websites using CVE-2026-58444
United States192 websites



Germany206 websites
France104 websites
Russia47 websites
Singapore42 websites
China23 websites
Czech Republic18 websites
Netherlands16 websites
GB15 websites
Canada10 websites

Website Distribution by TLD

Number of websites using CVE-2026-58444
.com191 websites
.net78 websites
.org77 websites
.de77 websites
.ru32 websites
.fr27 websites
.eu16 websites
.nl14 websites
.io12 websites
.cz11 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-58444

Top websites that are affected by CVE-2026-58444. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.********.com United States***,***
***.*************.org United States***,***
*****.**********.eu Germany***,***
***.*******.net United States***,***
******************.com United States*,***,***
**********.es France*,***,***
****.********.ch Switzerland*,***,***
***.*******.fi Finland*,***,***
***.*********.rip Germany*,***,***
***.************.com France*,***,***
See full domain list

FAQ

CVE-2026-58444 is Incorrect Authorization in Gitea
A total of 777 websites have been identified as vulnerable to CVE-2026-58444, based on global website indexing conducted by WebTechSurvey.
The Gitea is affected by the CVE-2026-58444 vulnerability.
Gitea versions up to 1.27 are vulnerable to CVE-2026-58444.
CVE-2026-58444 is resolved in version 1.27 of Gitea.