Vulnerability Report: GO-2026-6053
- CVE-2026-58429, GHSA-fq2p-5p22-8g6j
- Affects: gitea.dev
- Published: Jul 22, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev
For detailed information about this vulnerability, visit https://github.com/go-gitea/gitea/security/advisories/GHSA-fq2p-5p22-8g6j.
Affected Packages
-
PathVersionsSymbols
Aliases
References
- https://github.com/go-gitea/gitea/security/advisories/GHSA-fq2p-5p22-8g6j
- https://github.com/go-gitea/gitea/commit/a34eac5ef42ada433a7c7dafb98f15c13d7ad74e
- https://github.com/go-gitea/gitea/commit/f2a1271f164569264c378fad720b0c000fff3336
- https://github.com/go-gitea/gitea/pull/37118
- https://github.com/go-gitea/gitea/pull/37773
- https://github.com/go-gitea/gitea/releases/tag/v1.27.0
- https://vuln.go.dev/ID/GO-2026-6053.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.