CVE-2026-89430
N/A
N/A
Summary
Gitea validated a push mirror's remote address against the [migrations] allow and block lists only when the mirror was created. Each synchronization passed the stored address directly to git push, so a name that later resolved to a blocked or internal address was still reached. A user with administrator access to a repository, which includes repositories they create themselves, could aim push mirror synchronization at internal Git services and force-push the repository's contents to them.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Gitea | Gitea | 0 <= 1.27.3 | affected |
Weaknesses
- CWE-367: CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
- CWE-918: CWE-918: Server-Side Request Forgery (SSRF)
References
- https://github.com/go-gitea/gitea/security/advisories/GHSA-hcgw-r9gf-8mph
- https://github.com/go-gitea/gitea/pull/39010
- https://github.com/go-gitea/gitea/pull/39426
- https://blog.gitea.com/release-of-28.0.0/
- https://github.com/go-gitea/gitea/releases/tag/v28.0.0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.