Sunday 26 July 2026 11:06:40 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#CVE-2026-58443


Gitea’s Permission Slip That Reached the Wrong Branch

Published: 21 July 2026 12:34Category: Vulnerabilities & Patch ManagementAuthor: NEONPALADIN

A critical authorization flaw in Gitea let tokens meant for public repositories indirectly write into private ones and trigger automation there.

Gitea’s Permission Wall Fractures, and That Matters Far Beyond One Token

Published: 21 July 2026 10:13Category: Vulnerabilities & Patch ManagementAuthor: NEONPALADIN

A critical authorization bug in Gitea raises a familiar but dangerous question: what happens when a token that should stay on the public side of the fence can still touch private branches and CI workflows?