Public Repository Tokens Can Update Private Pull Requests in Gitea
CVE-2026-58443

9.1CRITICAL

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-58443?

A vulnerability has been identified in Gitea, where public repository tokens are allowed to update private pull request head branches. This may enable unauthorized modifications to private pull requests, potentially compromising the integrity of private repositories. It is important for Gitea users to review their configurations and limit access to sensitive repositories to mitigate this risk.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ohxorud-dev
bircni
wxiaoguang
delvh
.