Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58443

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 9.6
EPSS Низкий

Описание

Public-only repository tokens can update private PR head branches

A flaw was found in Gitea. This vulnerability allows an attacker to use tokens intended for public repositories to modify private pull request (PR) branches. This could lead to unauthorized changes in private code, compromising the integrity of the affected repositories.

Отчет

A flaw was found in Gitea where public-only repository tokens can be used to write to private pull request head branches. This authorization bypass allows an attacker with a valid public-only write:repository token to modify private repository branches through public base repository API endpoints, bypassing the public-only token restriction. This could lead to unauthorized changes in private code, compromising the integrity of affected repositories and potentially triggering private workflow executions when Actions is enabled.

Меры по смягчению последствий

Update to Gitea 1.27.0 or later. As a workaround, restrict the use of public-only tokens in environments where both public and private repositories with pull request relationships exist, or implement additional access controls at the API gateway level to prevent access to pull request update endpoints.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines-clientAffected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2515465code.gitea.io/gitea: Gitea: Unauthorized update of private pull request branches via public-only tokens

EPSS

Процентиль: 45%
0.00578
Низкий

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
около 1 месяца назад

Public-only repository tokens can update private PR head branches

redos
около 1 месяца назад

Уязвимость gitea

redos
около 1 месяца назад

Уязвимость gitea

CVSS3: 9.6
github
около 2 месяцев назад

Gitea: Public-only repository tokens can update private PR head branches

EPSS

Процентиль: 45%
0.00578
Низкий

9.6 Critical

CVSS3