CVE-2026-58431
An attacker can exploit multiple vulnerabilities in Gitea to execute arbitrary code, gain elevated permissions, bypass security measures, manipulate data, disclose sensitive information, hijack or reuse sessions, or trigger a denial-of-service state.
CSIRTS triage
- What
- Multiple vulnerabilities in Gitea can be exploited by an attacker to execute arbitrary code, gain elevated permissions, bypass security measures, manipulate data, disclose sensitive information, hijack sessions, or trigger a denial-of-service state.
- Who is affected
- Attackers targeting systems running the affected versions of Gitea.
- Urgency
- Remediation is high urgency due to the wide range of potential impacts including remote code execution and privilege escalation.
- Action
- Update to the latest version of Gitea.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-58431
Get an email if CVE-2026-58431 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Advisory coverage (2)
- mediumGHSA-h56g-4qw7-2mxg: Gitea: Public-only API token restriction is not enforced on team API routesghsa · 2026-07-21
- high[NEW] [high] Gitea: Multiple vulnerabilitiescert-bund · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-58431)