Executive brief
Gitea is a self-hosted software development platform used to manage source code. A security flaw allows users with basic write access to bypass branch protection rules, which are intended to prevent unauthorized changes to critical code. By manipulating pull request settings, an attacker can merge unapproved or malicious code into protected branches, potentially compromising the integrity of the software and bypassing mandatory security reviews.
Technical details
A logic flaw exists in Gitea's pull request handling where the 'official' approval flag is stored as a static boolean upon review submission but is not re-validated when the PR is retargeted. An attacker with write access can create a PR against an unprotected branch, obtain an 'official' approval from a non-whitelisted accomplice, and then retarget the PR to a protected branch (e.g., 'master'). Because Gitea's merge check (GetGrantedApprovalsCount) relies on the stored database flag rather than re-checking the new target branch's whitelist, the stale approval satisfies protection requirements. This allows unauthorized merging into protected branches. The issue is addressed in Gitea 1.27.0.
Affected products
- Gitea Gitea < 1.27.0
Timeline
- 2026-07-13: disclosed
- 2026-07-21: advisory