CVE-2026-89430
Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created. Each synch
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Oct 6, 2026 · Last modified: Oct 6, 2026 · CWE-367 · CWE-918
Not enough EPSS history yet.
Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created. Each synchronization passed the stored address directly to `git push`, so a name that later resolved to a blocked or internal address was still reached. A user with administrator access to a repository, which includes repositories they create themselves, could aim push mirror synchronization at internal Git services and force-push the repository's contents to them.
- blog.gitea.comhttps://blog.gitea.com/release-of-28.0.0/
- github.comhttps://github.com/go-gitea/gitea/pull/39010
- github.comhttps://github.com/go-gitea/gitea/pull/39426
- github.comhttps://github.com/go-gitea/gitea/releases/tag/v28.0.0
- github.comhttps://github.com/go-gitea/gitea/security/advisories/GHSA-hcgw-r9gf-8mph