CVE-2026-58429
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
4.9 / 10
Vulnerability Description
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
Vulnerability Details
Published Date
Last Modified
Source
GitHub
Vendor
go
Product
code.gitea.io/gitea
External References
- https://github.com/go-gitea/gitea/security/advisories/GHSA-fq2p-5p22-8g6j
- https://github.com/go-gitea/gitea/pull/37118
- https://github.com/go-gitea/gitea/pull/37773
- https://github.com/go-gitea/gitea/commit/a34eac5ef42ada433a7c7dafb98f15c13d7ad74e
- https://github.com/go-gitea/gitea/commit/f2a1271f164569264c378fad720b0c000fff3336
- https://github.com/go-gitea/gitea/releases/tag/v1.27.0
- https://github.com/advisories/GHSA-fq2p-5p22-8g6j
Discussion (0)
Add Comment
No comments yet. Be the first!