Threat Advisory

Gitea Flaws Enable Admin Access Without Authentication and Evade Authorization

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Gitea has addressed vulnerabilities including server-side request forgery (SSRF), authentication bypasses, account takeover risks, Gitea Actions approval bypasses, cross-site scripting, privacy issues, and OAuth token flaws. The vulnerabilities can allow authenticated users or users under specific configurations to access internal services, obtain unauthorized administrative sessions, execute unapproved workflows, expose private repository data, or compromise CI runners. Several vulnerabilities were addressed in the initial release while additional issues were fixed in the subsequent release. No confirmed active exploitation or public proof-of-concept has been reported. Organizations should apply the latest Gitea patches and review Actions workflows, migration settings, installer exposure, and recent repository activity.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Gitea has addressed vulnerabilities including server-side request forgery (SSRF), authentication bypasses, account takeover risks, Gitea Actions approval bypasses, cross-site scripting, privacy issues, and OAuth token flaws. The vulnerabilities can allow authenticated users or users under specific configurations to access internal services, obtain unauthorized administrative sessions, execute unapproved workflows, expose private repository data, or compromise CI runners. Several vulnerabilities were addressed in the initial release while additional issues were fixed in the subsequent release. No confirmed active exploitation or public proof-of-concept has been reported. Organizations should apply the latest Gitea patches and review Actions workflows, migration settings, installer exposure, and recent repository activity.[emaillocker id="1283"]

CVE-2026-94205 (CVSS 9.8 — Critical): A Gitea Actions approval bypass allows fork-controlled workflow code to execute on base repository runners without explicit approval when a maintainer triggers a pull request event.

CVE-2026-103059 (CVSS 9.1 — Critical): A case-insensitive key lookup on databases such as SQLite could match an attacker's crafted key to another user, affecting the built-in SSH server.

CVE-2026-95106 (CVSS 9.1 — Critical): A Gitea vulnerability allows duplicate Git tree entries to cause inconsistent file resolution enabling contributors to present benign content in pull request views while git checkout, CI, and other operations use attacker-controlled content.

CVE-2026-101023 (CVSS 9.1 — Critical): A Gitea OAuth2 token validation flaw allows an unexpired access token to be exchanged for a new access token and refresh token potentially extending unauthorized access beyond the original token lifetime.

CVE-2026-104632 (CVSS 8.8 — High): A Gitea Actions approval bypass allows fork pull request workflow code to run on repository runners without explicit maintainer approval when a pending run is cancelled and re-run.

CVE-2026-104626 (CVSS 8.8 — High): A Gitea Actions concurrency flaw allows fork-controlled workflow code to execute on repository runners after a blocked run is cancelled, re-run, and later approved by a maintainer.

CVE-2026-89430 (CVSS 8.1 — High): A Gitea push mirror validation flaw allows repository administrators to redirect mirror synchronization to blocked or internal addresses, causing git push to force-push repository contents to internal Git services.

CVE-2026-96404 (CVSS 8.1 — High): Submitting a matching admin username issues an authenticated session for that account without verifying its password, affecting the web installer.

CVE-2026-101027 (CVSS 7.7 — High): A Gitea migration SSRF bypass allows users controlling an ALLOWED_DOMAINS hostname to resolve it to loopback or private addresses, bypassing ALLOW_LOCALNETWORKS = false and reaching internal services from the Gitea server.

CVE-2026-96589 (CVSS 4.3 — Medium): A Gitea repository transfer flaw allows a recipient to retain read access to a private repository after a transfer is rejected or cancelled, enabling access to its code and other repository data.

 

RECOMMENDATIONS:

  • We recommend you to update Gitea to version 28.1.0 or later.

 

REFERENCES:

The following reports contain further technical details:
https://securityonline.info/gitea-security-update-28/

[/emaillocker]
crossmenu