---
id: CVE-2026-58443
title: >-
  code.gitea.io/gitea: Gitea: Unauthorized update of private pull request
  branches via public-only tokens (CVE-2026-58443)
summary: >-
  A flaw was found in Gitea. This vulnerability allows an attacker to use tokens
  intended for public repositories to modify private pull request (PR) branches.
  This could lead to unauthorized changes in private code, compromising the
  integri…
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H'
cvssSource: vendor
cwe:
  - CWE-266
  - CWE-863
vendor: Red Hat
product: OpenShift Pipelines
affected:
  - openshift_pipelines
patched:
  - code.gitea.io/gitea 1.27.0
published: '2026-08-13'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:41:11+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58443.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58443.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-58443'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2515465'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-58443'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-58443'
  - url: 'https://blog.gitea.com/gitea-1.27.0-is-released/'
  - url: 'https://github.com/go-gitea/gitea/releases/tag/v1.27.0'
  - url: 'https://github.com/go-gitea/gitea/security/advisories/GHSA-xxjv-752h-3vp2'
  - url: 'https://github.com/advisories/GHSA-xxjv-752h-3vp2'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - go
epss: 0.00579
epssPercentile: 0.45224
aliases:
  - GHSA-xxjv-752h-3vp2
ecosystem: go
ingestedAt: '2026-07-21T20:54:26.853Z'
---

## Overview

A flaw was found in Gitea. This vulnerability allows an attacker to use tokens intended for public repositories to modify private pull request (PR) branches. This could lead to unauthorized changes in private code, compromising the integrity of the affected repositories.

## Vendor advisories

- **Red Hat VEX** · Critical · affected: OpenShift Pipelines · no fix planned: OpenShift Pipelines · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-58443.json)

**code.gitea.io/gitea: Gitea: Unauthorized update of private pull request branches via public-only tokens** — rated Critical by Red Hat. Released 2026-08-13, updated 2026-09-23.

Affected:

- OpenShift Pipelines

No fix planned:

- OpenShift Pipelines

## Remediation

Will not fix

Workarounds / mitigations:

- Update to Gitea 1.27.0 or later. As a workaround, restrict the use of public-only tokens in environments where both public and private repositories with pull request relationships exist, or implement additional access controls at the API gateway level to prevent access to pull request update endpoints.

## Package advisory (CVE-2026-58443)

Affected packages:

- `code.gitea.io/gitea < 1.27.0`

Patched in:

- `code.gitea.io/gitea 1.27.0`

Source: https://github.com/advisories/GHSA-xxjv-752h-3vp2
