Authorization Bypass Through User-Controlled Key Affecting github.com/go-gitea/gitea/services/lfs package, versions <1.27.0


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.19% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Authorization Bypass Through User-Controlled Key vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMGOGITEAGITEASERVICESLFS-18752808
  • published13 Aug 2026
  • disclosed21 Jul 2026
  • creditAdrian Denkiewicz

Introduced: 21 Jul 2026

CVE-2026-58435  (opens in a new tab)
CWE-266  (opens in a new tab)
CWE-639  (opens in a new tab)

How to fix?

Upgrade github.com/go-gitea/gitea/services/lfs to version 1.27.0 or higher.

Overview

Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via the JWT authorization. An attacker can gain unauthorized access to LFS objects belonging to other repositories by leveraging a write deploy key and knowledge of valid object identifiers.

Note: This is only exploitable if the attacker possesses a write deploy key for a repository owned by the victim and knows the SHA-256 OID of the target LFS object.

CVSS Base Scores

version 4.0
version 3.1