๐Ÿ” CVE Alert

CVE-2026-79960

UNKNOWN 0.0

Gitea deploy key pushes acting as the repository owner

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

When a push was authenticated with a deploy key, Gitea recorded the repository owner as the pusher, so permission checks in the push hook pipeline evaluated the owner instead of the deploy key. A holder of a writable deploy key could create protected tags without being on the tag allow list and change repository visibility through push options, for example making a private repository public. Pull requests created through the AGit flow with a deploy key were also attributed to the owner.

CWE CWE-863
Vendor gitea
Product gitea
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for gitea gitea

Be the first to know when new unknown vulnerabilities affecting gitea gitea are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Gitea / Gitea
0 โ‰ค 1.27.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/go-gitea/gitea/security/advisories/GHSA-7769-9pr9-m24h github.com: https://github.com/go-gitea/gitea/pull/37306 blog.gitea.com: https://blog.gitea.com/release-of-28.0.0/ github.com: https://github.com/go-gitea/gitea/releases/tag/v28.0.0

Credits

๐Ÿ” https://github.com/1K0CT https://github.com/ToastyTheBot https://github.com/silverwind https://github.com/bircni https://github.com/wxiaoguang