#cve202658443

2 posts · Last used 4d

Back to Timeline
OffSequence @offseq@infosec.exchange · 4d ago
Gitea <1.27.0 CRITICAL vuln (CVE-2026-58443): Public-only write tokens can update private PR head branches, violating repo access controls. Patch pending — review token use & monitor vendor updates. https://radar.offseq.com/threat/gitea-public-only-repository-tokens-can-update-private-pr-head-branches-cve-2026-58443-d058444d84b9595a #OffSeq #Gitea #Vuln #CVE202658443
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 6d ago
Gitea vulnerability CVE-2026-58443 (CVSS 9.6) lets public-only tokens write to private repos. Details and PoC code are public. Update to v1.27.0. #Gitea #CVE202658443 #DevSecOps #PoC #InfoSec https://securityonline.info/gitea-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0

You've seen all posts