Description
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
Published: 2026-08-13
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to bypass branch protection rules by retaining a stale official approval flag after a pull request (PR) is retargeted to a different branch. The stale approval is not cleared or re‑validated when the PR target changes, meaning the PR can be merged or pushes can be performed on a protected branch without revoking the previous approval. This effectively grants a user the ability to push code to protected branches, undermining the repository’s security model and enabling potential tampering or deployment of malicious code.

Affected Systems

The affected product is Gitea, the open source Git server. No specific version range is listed in the CNA data, but the advisory references the release of Gitea 1.27.0 as a fix, indicating that versions prior to that are vulnerable.

Risk and Exploitability

The CVSS score is not provided and the EPSS score is unavailable, so the exploitation probability cannot be quantified from the data. The vulnerability is listed as not in the CISA KEV catalog. The likely attack vector is via the web interface or REST API that allows a user to retarget a PR to a new branch, after which the system mistakenly preserves the existing official approval flag. An attacker with access to create or modify PRs in a repository could exploit this to push changes to protected branches. The lack of an explicit fix or workaround in the CNA data indicates that the only reliable mitigation is to update to a patched version.

Generated by OpenCVE AI on August 13, 2026 at 19:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Gitea to version 1.27.0 or later to apply the official fix for stale approval handling.
  • Revoke or refresh all existing official approvals on pull requests that were approved before upgrading, ensuring no stale approvals remain active.
  • Disable or restrict PR retargeting for protected branches, requiring fresh approvals whenever a PR target changes.

Generated by OpenCVE AI on August 13, 2026 at 19:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-w5pg-649r-p6gg Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
History

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Gitea
Gitea gitea Open Source Git Server
Vendors & Products Gitea
Gitea gitea Open Source Git Server

Thu, 13 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
Title Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
Weaknesses CWE-284
References

Subscriptions

Gitea Gitea Open Source Git Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Gitea

Published:

Updated: 2026-08-13T16:44:53.887Z

Reserved: 2026-06-30T18:57:20.616Z

Link: CVE-2026-58439

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T17:17:27.913

Modified: 2026-08-13T17:17:27.913

Link: CVE-2026-58439

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T19:15:03Z

Weaknesses