CVE Watchtower ← Back to CVE ListCVE-2026-58443NVDDescriptionPublic-only repository tokens can update private PR head branchesSeverity LevelCRITICAL (9.1)Published Date13/08/2026Last Modified26/08/2026Exploitation Status????EPSS Score0.58% (percentile 46.3%)CVSS Base MetricsCVSS v3 (3.1)CRITICAL 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HWeaknesses (CWE)CWE-863Referenceshttps://blog.gitea.com/gitea-1.27.0-is-released/https://github.com/go-gitea/gitea/releases/tag/v1.27.0https://github.com/go-gitea/gitea/security/advisories/GHSA-xxjv-752h-3vp2https://github.com/go-gitea/gitea/security/advisories/GHSA-xxjv-752h-3vp2