CVE-2026-89182
Gitea push-to-create bypass of FORCE_PRIVATE policy
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The default configuration is not affected.
| CWE | CWE-863 |
| Vendor | gitea |
| Product | gitea |
| Published | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for gitea gitea
Be the first to know when new unknown vulnerabilities affecting gitea gitea are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Gitea / Gitea
1.27.0 โค 28.0.0
References
github.com: https://github.com/go-gitea/gitea/security/advisories/GHSA-fx95-gwfc-grgc github.com: https://github.com/go-gitea/gitea/pull/39501 github.com: https://github.com/go-gitea/gitea/pull/39507 blog.gitea.com: https://blog.gitea.com/release-of-28.1.0/ github.com: https://github.com/go-gitea/gitea/releases/tag/v28.1.0
Credits
๐ https://github.com/manus-pi https://github.com/silverwind https://github.com/bircni