VYPR
Unrated severityNVD Advisory· Published Oct 6, 2026

CVE-2026-89430

CVE-2026-89430

Description

Gitea validated a push mirror's remote address against the [migrations] allow and block lists only when the mirror was created. Each synchronization passed the stored address directly to git push, so a name that later resolved to a blocked or internal address was still reached. A user with administrator access to a repository, which includes repositories they create themselves, could aim push mirror synchronization at internal Git services and force-push the repository's contents to them.

Affected products

2
  • Go Gitea/Giteareferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.

CVE-2026-89430 · VYPR