VYPR
patchPublished Oct 8, 2026· 1 source

Gitea Patches 27 Security Flaws, Including Critical SSH Auth Bypass and SSRF

Gitea has released version 28.1.0, addressing 27 vulnerabilities, notably a critical SSH authentication bypass (CVE-2026-103059) and several SSRF flaws.

Gitea, a popular open-source Git service, has issued a significant security update, version 28.1.0, to address a total of 27 vulnerabilities discovered across its platform. The patches tackle critical issues including an SSH authentication bypass and multiple server-side request forgery (SSRF) vulnerabilities, alongside fixes for Gitea Actions, cross-site scripting (XSS), and permission-related weaknesses. Administrators are urged to prioritize this update to protect their development infrastructure.

The most critical vulnerability, identified as CVE-2026-103059, carries a CVSS score of 9.1 and affects deployments utilizing Gitea's integrated SSH server. The flaw stems from an SQL LIKE comparison used in the public-key lookup process, which, on certain databases like the default SQLite, is case-insensitive. This weakness could allow an attacker to craft a specially modified RSA key that matches another user's registered key. If the attacker can then derive the corresponding private key, they could authenticate as the targeted victim. Gitea has since rectified this by implementing a new method that identifies presented keys through their fingerprints, eliminating the vulnerable text-based comparison.

Several other vulnerabilities patched in this release relate to repository migrations and mirrors, which previously allowed them to bypass outbound connection rules. CVE-2026-70357, for instance, exploited a timing gap between hostname validation and the actual Git connection. An attacker could manipulate the DNS response during this window, redirecting Gitea to an internal host after the initial security checks had passed. Additional SSRF flaws, CVE-2026-101027 and CVE-2026-101029, permitted the bypass of outbound allowlists by either skipping destination IP checks for approved domains or by leveraging multiple DNS answers.

Further exacerbating the SSRF risks, CVE-2026-89430 allowed push mirrors to connect to internal Git hosts even after their saved addresses had passed an initial verification. This could potentially enable forced pushes to internal repositories. To mitigate these risks, Gitea has implemented a new routing mechanism for Git network operations, directing them through an internal proxy that enforces outbound access rules at the point of connection. Administrators are advised to carefully review the configuration changes required for this new proxy system before upgrading.

The update also addresses security gaps within Gitea Actions, the platform's workflow automation feature. CVE-2026-104632 allowed canceled, approval-pending fork workflows to execute on self-hosted runners when rerun. Separately, CVE-2026-94205 failed to adequately check the event actor, permitting a maintainer-triggered event to run an untrusted contributor's workflow without the necessary approval. Both of these issues have been tightened in the latest release.

Beyond these critical flaws, the security update resolves several other issues. These include stored XSS vulnerabilities within container blobs, a problem where duplicate Git tree entries could obscure malicious files from reviewers, and an installer flaw that could issue an existing administrator's session without requiring a password re-authentication. Permission-related fixes also address lingering repository-transfer access issues and prevent deploy keys from inheriting repository-owner privileges.

Administrators planning to upgrade should ensure they back up their data, carefully review the release notes for any breaking changes, and proceed to update to version 28.1.0. The release notes provide detailed information on the new network rules, the updated minimum Git version requirement (2.25), and other behavioral changes in Gitea Actions. Previous reports on Gitea RCE exploitation and private repository permission bypasses highlight the ongoing importance of timely patching for this platform.

Synthesized by Vypr AI