Insufficient Logging Affecting github.com/go-gitea/gitea/routers/private package, versions <1.27.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.21% (11th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Insufficient Logging vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMGOGITEAGITEAROUTERSPRIVATE-18677520
  • published12 Aug 2026
  • disclosed21 Jul 2026
  • creditGhost 💀

Introduced: 21 Jul 2026

CVE-2026-58437  (opens in a new tab)
CWE-778  (opens in a new tab)

How to fix?

Upgrade github.com/go-gitea/gitea/routers/private to version 1.27.0 or higher.

Overview

Affected versions of this package are vulnerable to Insufficient Logging through the processing of undocumented git push options in the HookPostReceive function. An attacker can change the visibility or template status of a repository without triggering audit logs, webhooks, or notifications by sending specially crafted git push options. This allows unauthorized changes to repository settings to go undetected, potentially exposing sensitive data or enabling supply chain attacks.

Note: This is only exploitable if the attacker has owner-level or admin collaborator access to the target repository.

CVSS Base Scores

version 4.0
version 3.1