PT-2026-63301 · Gitea+1 · Gitea+1

·

CVE-2026-58435

·

Published

2026-07-21

·

Updated

2026-08-26

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gitea version 1.25.5
Description An insufficient authorization issue exists in the LFS server where the system uses the UserID embedded in an LFS JWT to make cross-repository authorization decisions via the LFSObjectAccessible() function. When a deploy key is used for authentication, the system incorrectly sets the UserID to the repository owner's ID instead of an identity representing the deploy key. This allows an attacker with a write deploy key for any single repository owned by a victim to obtain a JWT that impersonates the victim. Consequently, the attacker can exfiltrate LFS objects from any private repository the victim owns, provided the attacker knows the SHA-256 OID of the target object. If the victim is a site administrator, all LFS objects on the Gitea instance may be accessible. The issue is reachable via the SSH git-lfs-authenticate command and the HTTP LFS batch API endpoint /info/lfs/objects/batch when LFS START SERVER is enabled.
Recommendations For version 1.25.5, remove the LFSObjectAccessible cross-repo shortcut in services/lfs/server.go to require proof of possession for any object not already linked to the target repository. For version 1.25.5, modify routers/private/serv.go to stop embedding the repo.OwnerID in the JWT for deploy keys, instead using a synthetic principal or a repo-scoped JWT type. As a temporary mitigation, restrict access to the LFS batch API endpoint /info/lfs/objects/batch to minimize the risk of exploitation.

Exploit

Fix

DoS

LPE

IDOR

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58435
GHSA-RH79-75QM-GWJR
GO-2026-6073
OPENSUSE-SU-2026:21551-1
SUSE-SU-2026:23216-1
SUSE-SU-2026:23227-1

Affected Products

Gitea
Red Os