CVE-2026-58417
gitea.dev: Improper Access Control (CVE-2026-58417)
highEPSS 0.3 %
Beschreibung
Metriken
Severity
high
83.77
kein öffentlicher PoC bekannt
7.5
Veröffentlicht
2026-08-13 16:44 UTC
CWE-284
Weakness-Klassen (CWE)
CWE-284Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
cwe.mitre.org →
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
go
gitea.dev
Quellen & Referenzen
- https://github.com/go-gitea/gitea/security/advisories/GHSA-jr5x-6h83-wrxfadvisory
- https://github.com/go-gitea/gitea/commit/685b62c60fc595e3612a85f0895471876db56292web
- https://github.com/go-gitea/gitea/pull/38145web
- https://github.com/go-gitea/gitea/releases/tag/v1.27.0web
- https://blog.gitea.com/gitea-1.27.0-is-released/release-notes
IDCVE-2026-58417