EXECUTIVE SUMMARY:
Multiple vulnerabilities have been identified in Gitea, including a critical SSH authentication bypass and server-side request forgery weaknesses. The flaws affect account access, repository permissions, automated workflows and connections to internal systems. Administrators should prioritize applying the available updates to protect their development infrastructure.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Multiple vulnerabilities have been identified in Gitea, including a critical SSH authentication bypass and server-side request forgery weaknesses. The flaws affect account access, repository permissions, automated workflows and connections to internal systems. Administrators should prioritize applying the available updates to protect their development infrastructure.[emaillocker id="1283"]
CVE-2026-70357 (CVSS 7.5 — High): An attacker could change the hostname's DNS response during a gap between hostname validation and the actual Git connection, directing Gitea toward an internal host after the initial security check passed.
CVE-2026-101029 (CVSS 4.3 — Medium): A network access control bypass involving multiple DNS responses could circumvent outbound host allowlists and enable connections to unintended destinations.
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://cybersecuritynews.com/gitea-patches-27-security-flaws/