securityonline.info 7/20/2026, 4:11:15 PM · external

CVE-2026-58443: Gitea Flaw (CVSS 9.6) Details and PoC Exploit Code Publicly Disclosed

CVE-2026-58443: Gitea Flaw (CVSS 9.6) Details and PoC Exploit Code Publicly Disclosed
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability in Gitea, CVE-2026-58443 (CVSS 9.6), allows public-only tokens to push commits to private repositories, breaching intended access restrictions. The flaw is present in all versions up to v1.26.4 and has been addressed in v1.27.0. No in-the-wild exploitation has been confirmed, but the public availability of a proof-of-concept (PoC) makes potential attacks more feasible. Affected users are advised to upgrade immediately or audit their token scopes to mitigate risks. The weakness exploits how Gitea handles public-only token restrictions during pull request updates.

View Primary Source Via securityonline.info

Article by CyberSIXT