<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T01:16:08.888704+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-58439</id>
    <title>CVE-2026-58439 — Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag</title>
    <updated>2026-10-08T01:16:08.891537+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Gitea Open Source Git Server</p>
<p>Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-58439"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w5pg-649r-p6gg</id>
    <title>GHSA-w5pg-649r-p6gg — Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag</title>
    <updated>2026-10-08T01:16:08.891598+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.gitea.io/gitea</p>
<p>## Summary</p>
<p>Gitea does not re-evaluate the `official` flag on existing pull request reviews when a PR's target branch is changed. An attacker with write access to a repository can obtain an `official: true` approval on a PR targeting an unprotected branch, then retarget the PR to a protected branch (e.g., `master`). The approval, which would have been `official: false` if submitted against the protected branch, is preserved and satisfies the protected branch's required approvals, allowing the attacker to merge without legitimate maintainer approval.</p>
<p>- Confirmed on Gitea **1.25.4** (`1.25.4+41-g96515c0f20`)</p>
<p>## Vulnerability Details</p>
<p>### Root Cause</p>
<p>When a review is submitted on a pull request, Gitea computes the `official` flag by checking whether the reviewer is in the **target branch's** approval whitelist (`IsUserOfficialReviewer` in `models/git/protected_branch.go`). This flag is stored in the database as a boolean on the review record.</p>
<p>When a PR's target branch is subsequently changed via `ChangeTargetBranch` (`services/pull/pull.go:218`), the function:
- Updates `pr.BaseBranch`
- Recalculates merge feasibility and divergence
- Deletes old push comments
- Creates a "change target branch" comment</p>
<p>But it does **not**:
- Re-evaluate `official` on existing reviews
- Dismiss existing approvals
- Check whether reviewers are in the new target branch's approval whitelist</p>
<p>At merge time, `GetGrantedApprovalsCount` (`models/issues/pull.go:766`) counts reviews where `official =…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w5pg-649r-p6gg"/>
  </entry>
</feed>
