Vulnerability Report: GO-2026-6080
- CVE-2026-58439, GHSA-w5pg-649r-p6gg
- Affects: code.gitea.io/gitea
- Published: Jul 27, 2026
- Unreviewed
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag in go-gitea/gitea. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: code.gitea.io/gitea before v1.27.0.
For detailed information about this vulnerability, visit https://github.com/go-gitea/gitea/security/advisories/GHSA-w5pg-649r-p6gg.
Affected Modules
-
PathGo VersionsCustom Versions*
-
all versions, no known fixedbefore 1.27.0
*Custom versions, which can't be mapped automatically to standard Go module versions, are ignored by govulncheck. (See this note on versions for more details.)
Aliases
References
- https://github.com/go-gitea/gitea/security/advisories/GHSA-w5pg-649r-p6gg
- https://github.com/go-gitea/gitea/commit/74ad781db9c37134ee9280c69a6b1de53801503e
- https://github.com/go-gitea/gitea/commit/8401fe7c544abff1ecc49d7f3166fd4ee0c174ef
- https://github.com/go-gitea/gitea/pull/38319
- https://github.com/go-gitea/gitea/pull/38402
- https://github.com/go-gitea/gitea/releases/tag/v1.27.0
- https://vuln.go.dev/ID/GO-2026-6080.json