Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58439

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 7.7
EPSS Низкий

Описание

Branch Protection Bypass via PR Retargeting Preserves Stale official Approval Flag

A flaw was found in Gitea. This vulnerability allows an attacker to bypass branch protection by retargeting a Pull Request (PR) that has a stale 'official' approval flag. This could lead to unauthorized code being merged into a protected branch, compromising code integrity.

Отчет

This is an Important flaw in Gitea that allows an attacker to bypass branch protection by manipulating pull requests with stale approval flags, potentially leading to unauthorized code merges and compromising code integrity. This is considered Important due to the potential for unauthorized code execution within a controlled environment, despite requiring specific user interaction.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines-clientNot affected
OpenShift Pipelinesopenshift-pipelines/pipelines-cli-tkn-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-opc-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-cli-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-controller-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-472
https://bugzilla.redhat.com/show_bug.cgi?id=2515489code.gitea.io/gitea: Gitea: Branch protection bypass via stale approval flag in PR retargeting

EPSS

Процентиль: 21%
0.00284
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
20 дней назад

Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

redos
20 дней назад

Уязвимость gitea

redos
20 дней назад

Уязвимость gitea

CVSS3: 8.1
github
около 1 месяца назад

Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

EPSS

Процентиль: 21%
0.00284
Низкий

7.7 High

CVSS3