UNKNOWN Go
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev
GO-2026-6053 · CVE-2026-58429 · GHSA-fq2p-5p22-8g6j
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints in gitea.dev
References
- ADVISORY https://github.com/go-gitea/gitea/security/advisories/GHSA-fq2p-5p22-8g6j
- WEB https://github.com/go-gitea/gitea/commit/a34eac5ef42ada433a7c7dafb98f15c13d7ad74e
- WEB https://github.com/go-gitea/gitea/commit/f2a1271f164569264c378fad720b0c000fff3336
- WEB https://github.com/go-gitea/gitea/pull/37118
- WEB https://github.com/go-gitea/gitea/pull/37773
- WEB https://github.com/go-gitea/gitea/releases/tag/v1.27.0
Ready to move
Start Securing
Free, no credit card | First findings in minutes