Public Repository Tokens Can Update Private Pull Requests in Gitea
CVE-2026-58443

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-58443?

A vulnerability has been identified in Gitea, where public repository tokens are allowed to update private pull request head branches. This may enable unauthorized modifications to private pull requests, potentially compromising the integrity of private repositories. It is important for Gitea users to review their configurations and limit access to sensitive repositories to mitigate this risk.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ohxorud-dev
bircni
wxiaoguang
delvh
.