CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-w5pg-649r-p6gg: Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

highCVSS 8.1CVE-2026-58439
Summary Gitea does not re-evaluate the official flag on existing pull request reviews when a PR's target branch is changed. An attacker with write access to a repository can obtain an official: true approval on a PR targeting an unprotected branch, then retarget the PR to a protected branch (e.g., master). The approval, which would have been official: false if submitted against the protected branch, is preserved and satisfies the protected branch's required approvals, allowing the attacker to merge without legitimate maintainer approval. - Confirmed on Gitea 1.25.4 (1.25.4+41-g96515c0f20) Vulnerability Details Root Cause When a review is submitted on a pull request, Gitea computes the official flag by checking whether the reviewer is in the target branch's approval whitelist (IsUserOfficialReviewer in models/git/protected_branch.go). This flag is stored in the database as a boolean on the review record. When a PR's target branch is subsequently changed via ChangeTargetBranch (services/pull/pull.go:218), the function: - Updates pr.BaseBranch - Recalculates merge feasibility and divergence - Deletes old push comments - Creates a "change target branch" comment But it does not: - Re-evaluate official on existing reviews - Dismiss existing approvals - Check whether reviewers are in the new target branch's approval whitelist At merge time, GetGrantedApprovalsCount (models/issues/pull.go:766) counts reviews where official = true AND dismissed = false AND type = Approve. It reads the stored boolean — it does not re-check the whitelist. The stale official: true from the unprotected branch satisfies the protected branch's approval requirement. Relevant Code Paths 1. Review creation — services/pull/review.go:SubmitReview calls IsOfficialReviewer against the current pr.BaseBranch's protection rules, stores official=true/false 2. Target branch change — services/pull/pull.go:ChangeTargetBranch modifies pr.BaseBranch but does not touch existing reviews 3. Merge check — s

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
high — CVSS 8.1
Published
2026-07-21
Last updated
2026-07-21
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-w5pg-649r-p6gg

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-58439coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from GitHub Security Advisories