Gitea.dev: Gitea: Public-only API token restriction is not enforced on team API routes (CVE-2026-58431)
Gitea versions prior to 1.27.0 have a vulnerability where the public-only API token restriction is not properly enforced on team API routes. This allows a public-only token, which should only access public repositories and organizations, to retrieve private team repository metadata and private team activity feed entries. The issue arises because the organization visibility check is bypassed due to missing organization context, and repository-level public-only filtering is not applied. This vulnerability has been verified on version 1.26.2 and nightly builds.
AI Analysis
Technical Summary
The vulnerability in Gitea's /api/v1/teams/{id} API routes stems from improper enforcement of the public-only token restriction. The middleware that checks token restrictions relies on organization visibility via ctx.Org.Organization, which is not loaded in these routes, causing the check to silently pass. Additionally, team repository handlers do not apply repository-level public-only access checks, and the team activity feed handler includes private data without filtering for public-only tokens. Consequently, a public-only token can access private team resources that should be restricted.
Potential Impact
An attacker or user with a public-only token can access private team repository metadata and private activity feed information that should be inaccessible. This leads to unintended information disclosure of private organizational resources, potentially exposing sensitive project details to unauthorized users.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, avoid using public-only tokens in contexts where team API routes might be accessed, or restrict API token usage to trusted users. Monitor vendor communications for updates and apply patches promptly once available.
Gitea.dev: Gitea: Public-only API token restriction is not enforced on team API routes (CVE-2026-58431)
Description
Gitea versions prior to 1.27.0 have a vulnerability where the public-only API token restriction is not properly enforced on team API routes. This allows a public-only token, which should only access public repositories and organizations, to retrieve private team repository metadata and private team activity feed entries. The issue arises because the organization visibility check is bypassed due to missing organization context, and repository-level public-only filtering is not applied. This vulnerability has been verified on version 1.26.2 and nightly builds.
CVSS v3.1
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Gitea's /api/v1/teams/{id} API routes stems from improper enforcement of the public-only token restriction. The middleware that checks token restrictions relies on organization visibility via ctx.Org.Organization, which is not loaded in these routes, causing the check to silently pass. Additionally, team repository handlers do not apply repository-level public-only access checks, and the team activity feed handler includes private data without filtering for public-only tokens. Consequently, a public-only token can access private team resources that should be restricted.
Potential Impact
An attacker or user with a public-only token can access private team repository metadata and private activity feed information that should be inaccessible. This leads to unintended information disclosure of private organizational resources, potentially exposing sensitive project details to unauthorized users.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, avoid using public-only tokens in contexts where team API routes might be accessed, or restrict API token usage to trusted users. Monitor vendor communications for updates and apply patches promptly once available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-h56g-4qw7-2mxg
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-58431"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a600aa29c2644c7f8fdfcc4
Added to database: 07/22/2026, 00:11:14 UTC
Last enriched: 07/22/2026, 00:39:07 UTC
Last updated: 07/22/2026, 00:39:07 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.