{"id":"CVE-2026-58443","title":"code.gitea.io/gitea: Gitea: Unauthorized update of private pull request branches via public-only tokens (CVE-2026-58443)","summary":"A flaw was found in Gitea. This vulnerability allows an attacker to use tokens intended for public repositories to modify private pull request (PR) branches. This could lead to unauthorized changes in private code, compromising the integri…","severity":"critical","cvss":9.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H","cvssSource":"vendor","cwe":["CWE-266","CWE-863"],"vendor":"Red Hat","product":"OpenShift Pipelines","affected":["openshift_pipelines"],"patched":["code.gitea.io/gitea 1.27.0"],"published":"2026-08-13","updated":"2026-09-07","sourceUpdated":"2026-09-07T05:56:42+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58443.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58443.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-58443"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515465"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-58443"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58443"},{"url":"https://blog.gitea.com/gitea-1.27.0-is-released/"},{"url":"https://github.com/go-gitea/gitea/releases/tag/v1.27.0"},{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-xxjv-752h-3vp2"},{"url":"https://github.com/advisories/GHSA-xxjv-752h-3vp2"}],"tags":["csaf","vex","red-hat","ghsa","go"],"epss":0.00578,"epssPercentile":0.46315,"aliases":["GHSA-xxjv-752h-3vp2"],"ecosystem":"go","ingestedAt":"2026-07-21T20:54:26.853Z","slug":"CVE-2026-58443","body":"## Overview\n\nA flaw was found in Gitea. This vulnerability allows an attacker to use tokens intended for public repositories to modify private pull request (PR) branches. This could lead to unauthorized changes in private code, compromising the integrity of the affected repositories.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Critical · affected: OpenShift Pipelines · no fix planned: OpenShift Pipelines · updated 2026-09-07 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58443.json)\n\n**code.gitea.io/gitea: Gitea: Unauthorized update of private pull request branches via public-only tokens** — rated Critical by Red Hat. Released 2026-08-13, updated 2026-09-07.\n\nAffected:\n\n- OpenShift Pipelines\n\nNo fix planned:\n\n- OpenShift Pipelines\n\n## Remediation\n\nAffected\n\nWorkarounds / mitigations:\n\n- Update to Gitea 1.27.0 or later. As a workaround, restrict the use of public-only tokens in environments where both public and private repositories with pull request relationships exist, or implement additional access controls at the API gateway level to prevent access to pull request update endpoints.\n\n## Package advisory (CVE-2026-58443)\n\nAffected packages:\n\n- `code.gitea.io/gitea < 1.27.0`\n\nPatched in:\n\n- `code.gitea.io/gitea 1.27.0`\n\nSource: https://github.com/advisories/GHSA-xxjv-752h-3vp2","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":52.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}