Threat Advisory

Gitea Vulnerabilities Expose Repository Access and Internal Network Connections

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in Gitea, including a critical SSH authentication bypass and server-side request forgery weaknesses. The flaws affect account access, repository permissions, automated workflows and connections to internal systems. Administrators should prioritize applying the available updates to protect their development infrastructure.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in Gitea, including a critical SSH authentication bypass and server-side request forgery weaknesses. The flaws affect account access, repository permissions, automated workflows and connections to internal systems. Administrators should prioritize applying the available updates to protect their development infrastructure.[emaillocker id="1283"]

CVE-2026-70357 (CVSS 7.5 — High): An attacker could change the hostname's DNS response during a gap between hostname validation and the actual Git connection, directing Gitea toward an internal host after the initial security check passed.

CVE-2026-101029 (CVSS 4.3 — Medium): A network access control bypass involving multiple DNS responses could circumvent outbound host allowlists and enable connections to unintended destinations.

 

RECOMMENDATIONS:

  • We recommend you to update Gitea to version 28.1.0 or later.

 

REFERENCES:

The following reports contain further technical details:
https://cybersecuritynews.com/gitea-patches-27-security-flaws/

[/emaillocker]
crossmenu