Gitea: 25 Vulnerabilities Disclosed Together, Including Critical Authentication Flaws
Go Gitea addressed 25 vulnerabilities disclosed on October 6, 2026, impacting authentication, repository management, and automated workflows, with several rated Critical.

Key findings
- 25 Gitea vulnerabilities disclosed on October 6, 2026, ranging from Medium to Critical severity.
- Flaws impact authentication, repository permissions, and automated workflows.
- Critical vulnerabilities include bypasses for authentication, approval gates, and improper handling of OAuth2 tokens.
- Several issues related to push mirrors and repository migrations could lead to unauthorized access or resource exhaustion.
- Gitea versions 28.0.0 and 28.1.0 contain fixes for this batch of vulnerabilities.
On October 6, 2026, Go Gitea released security updates addressing a batch of 25 vulnerabilities discovered in its open-source Git service. The vulnerabilities, disclosed within a two-hour window, range in severity from Medium to Critical, impacting various aspects of the platform including authentication, repository management, and automated workflows. These flaws highlight potential risks for organizations relying on Gitea for their development infrastructure.
Several vulnerabilities revolve around improper handling of repository and user permissions. CVE-2026-97626, a Medium severity flaw, allowed anonymous or restricted users to access an owner's activity feed by requesting a user profile with specific Accept headers, bypassing visibility checks. Similarly, CVE-2026-105268 (Medium) enabled users to rename or delete attachments belonging to an issue's comments, as the API did not distinguish between issue and comment attachments. CVE-2026-105267 (High) permitted collaborators with only code write access to delete tags, as the tag deletion endpoint shared a handler with release deletion and lacked proper checks. Furthermore, CVE-2026-89182 (Medium) allowed users to make newly created repositories public even when instance policies mandated private repositories, due to a flaw in the post-receive hook. CVE-2026-79960 (High) involved an issue where pushes authenticated with deploy keys were incorrectly attributed to the repository owner, allowing deploy key holders to bypass protected tag rules and alter repository visibility.
Authentication and access control were also compromised in several critical vulnerabilities. CVE-2026-97208 (Medium) bypassed a setting that disabled new push mirrors, allowing repository administrators to create them on instances where it was intended to be disallowed. CVE-2026-86684 (High) permitted repository administrators, even those not allowed to import local paths, to add push mirrors to local server paths on instances with IMPORT_LOCAL_PATHS = true. A critical flaw, CVE-2026-96404 (High), allowed an attacker to gain an authenticated session without verifying the password if the web installer's administrator username matched an existing account, particularly if INSTALL_LOCK was reset. CVE-2026-94205 (Critical) and CVE-2026-104632 (High) relate to Gitea Actions and fork pull request security, where approval gates could be bypassed, allowing unapproved code to be executed. CVE-2026-73278 (Critical) allowed attackers to obtain a full session without WebAuthn verification if it was the account's only second factor, bypassing the enforced passkey verification during password login. CVE-2026-101023 (Critical) involved an OAuth2 token endpoint that could be tricked into issuing new tokens using an unexpired access token instead of a refresh token.
Several vulnerabilities exploited insecure handling of external resources and data processing. CVE-2026-96594 (Medium) resulted in HTML files being rendered directly by the browser due to missing content type and disposition headers. CVE-2026-105267 (High) allowed collaborators with code write access to delete tags, as the tag deletion endpoint shared a handler with release deletion and lacked proper checks. CVE-2026-89182 (Medium) allowed users to make newly created repositories public even when instance policies mandated private repositories, due to a flaw in the post-receive hook. CVE-2026-79960 (High) involved an issue where pushes authenticated with deploy keys were incorrectly attributed to the repository owner, allowing deploy key holders to bypass protected tag rules and alter repository visibility.
The batch also includes vulnerabilities related to resource exhaustion and denial of service. CVE-2026-104633 (Medium) could lead to indefinite loops and memory exhaustion during repository migrations if the source server reported an max_response_items of 0. CVE-2026-95112 (Medium) described a performance issue where processing issue and comment bodies could take quadratic time, allowing authenticated users to submit crafted content that could exhaust server resources. CVE-2026-96399 (High) could lead to a runtime panic and Gitea process termination when rendering issue references due to malformed regular expressions in external issue tracker settings.
The disclosures also highlight issues with push mirrors and migrations. CVE-2026-96589 (Medium) meant that rejecting or canceling a private repository transfer did not revoke the recipient's temporary read access. CVE-2026-96400 (Medium) permitted reserved and link-local addresses in migration URLs under certain configurations, bypassing network blocks. CVE-2026-70357 (High) and CVE-2026-104636 (High) involved vulnerabilities where Gitea's validation of migration and push mirror URLs could be circumvented by DNS manipulation or HTTP redirects, allowing connections to unauthorized or internal network addresses.
Finally, CVE-2026-95106 (Critical) involved Gitea accepting Git trees with duplicate file names, leading to inconsistent behavior between web views and checkout/Actions processes. CVE-2026-96580 (High) described how a workflow's static strategy.matrix could expand without limit, consuming excessive resources before a pull request approval gate was applied. CVE-2026-104632 (High) detailed how rerunning Gitea Actions jobs from fork pull requests could bypass pending approval checks. CVE-2026-104626 (High) allowed users to place workflow content into a Gitea Actions run awaiting approval, leading to a terminal state that appeared to need approval. CVE-2026-103670 (High) involved the cancellation of older Gitea Actions runs in a concurrency group without checking for pending approval, potentially allowing untrusted fork pull requests to cancel in-progress, approved runs.
These vulnerabilities were addressed in Gitea versions 28.0.0 and 28.1.0. Administrators are urged to update their instances as soon as possible to mitigate these risks.
The Cyber Security News article highlights that Gitea released security updates addressing 27 flaws, including critical SSH authentication bypass and SSRF weaknesses, across versions 28.0.0 and 28.1.0. The fixes cover account access, repository permissions, automated workflows, and connections to internal systems, emphasizing the urgent need for administrators to update their development infrastructure.
CVE-2026-97626, CVE-2026-97208, CVE-2026-96594, CVE-2026-89182, CVE-2026-86684, CVE-2026-105268, CVE-2026-105267, CVE-2026-104633, CVE-2026-101023, CVE-2026-96589, CVE-2026-96580, CVE-2026-96404, CVE-2026-96400, CVE-2026-96399, CVE-2026-95112, CVE-2026-95106, CVE-2026-94205, CVE-2026-89430, CVE-2026-79960, CVE-2026-73278, CVE-2026-70357, CVE-2026-104636, CVE-2026-104632, CVE-2026-104626, CVE-2026-103670.