CVE-2026-58420: Gitea Legacy Csrf Protector

Legacy custom cookie-based CSRF protector implementation is deprecated in favor of CrossOriginProtection.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Go
greprules fetch cve-2026-58420-gitea-legacy-csrf-protector --engine opengrep

Description

Legacy custom cookie-based CSRF protector implementation is deprecated in favor of CrossOriginProtection.