<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 00:27:26 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-58439 — Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-58439</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Gitea Open Source Git Server&lt;/p&gt;
&lt;p&gt;Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Gitea Open Source Git Server&lt;/p&gt;
&lt;p&gt;Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-58439</guid>
    </item>
    <item>
      <title>GHSA-w5pg-649r-p6gg — Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w5pg-649r-p6gg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Gitea does not re-evaluate the `official` flag on existing pull request reviews when a PR&amp;#39;s target branch is changed. An attacker with write access to a repository can obtain an `official: true` approval on a PR targeting an unprotected branch, then retarget the PR to a protected branch (e.g., `master`). The approval, which would have been `official: false` if submitted against the protected branch, is preserved and satisfies the protected branch&amp;#39;s required approvals, allowing the attacker to merge without legitimate maintainer approval.&lt;/p&gt;
&lt;p&gt;- Confirmed on Gitea **1.25.4** (`1.25.4+41-g96515c0f20`)&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;When a review is submitted on a pull request, Gitea computes the `official` flag by checking whether the reviewer is in the **target branch&amp;#39;s** approval whitelist (`IsUserOfficialReviewer` in `models/git/protected_branch.go`). This flag is stored in the database as a boolean on the review record.&lt;/p&gt;
&lt;p&gt;When a PR&amp;#39;s target branch is subsequently changed via `ChangeTargetBranch` (`services/pull/pull.go:218`), the function:
- Updates `pr.BaseBranch`
- Recalculates merge feasibility and divergence
- Deletes old push comments
- Creates a &amp;#34;change target branch&amp;#34; comment&lt;/p&gt;
&lt;p&gt;But it does **not**:
- Re-evaluate `official` on existing reviews
- Dismiss existing approvals
- Check whether reviewers are in the new target branch&amp;#39;s approval whitelist&lt;/p&gt;
&lt;p&gt;At merge time, `GetGrantedApprovalsCount` (`models/issues/pull.go:766`) counts reviews where `official =…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Gitea does not re-evaluate the `official` flag on existing pull request reviews when a PR&amp;#39;s target branch is changed. An attacker with write access to a repository can obtain an `official: true` approval on a PR targeting an unprotected branch, then retarget the PR to a protected branch (e.g., `master`). The approval, which would have been `official: false` if submitted against the protected branch, is preserved and satisfies the protected branch&amp;#39;s required approvals, allowing the attacker to merge without legitimate maintainer approval.&lt;/p&gt;
&lt;p&gt;- Confirmed on Gitea **1.25.4** (`1.25.4+41-g96515c0f20`)&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;When a review is submitted on a pull request, Gitea computes the `official` flag by checking whether the reviewer is in the **target branch&amp;#39;s** approval whitelist (`IsUserOfficialReviewer` in `models/git/protected_branch.go`). This flag is stored in the database as a boolean on the review record.&lt;/p&gt;
&lt;p&gt;When a PR&amp;#39;s target branch is subsequently changed via `ChangeTargetBranch` (`services/pull/pull.go:218`), the function:
- Updates `pr.BaseBranch`
- Recalculates merge feasibility and divergence
- Deletes old push comments
- Creates a &amp;#34;change target branch&amp;#34; comment&lt;/p&gt;
&lt;p&gt;But it does **not**:
- Re-evaluate `official` on existing reviews
- Dismiss existing approvals
- Check whether reviewers are in the new target branch&amp;#39;s approval whitelist&lt;/p&gt;
&lt;p&gt;At merge time, `GetGrantedApprovalsCount` (`models/issues/pull.go:766`) counts reviews where `official =…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w5pg-649r-p6gg</guid>
    </item>
  </channel>
</rss>
