๐Ÿ” CVE Alert

CVE-2026-89182

UNKNOWN 0.0

Gitea push-to-create bypass of FORCE_PRIVATE policy

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The default configuration is not affected.

CWE CWE-863
Vendor gitea
Product gitea
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for gitea gitea

Be the first to know when new unknown vulnerabilities affecting gitea gitea are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Gitea / Gitea
1.27.0 โ‰ค 28.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/go-gitea/gitea/security/advisories/GHSA-fx95-gwfc-grgc github.com: https://github.com/go-gitea/gitea/pull/39501 github.com: https://github.com/go-gitea/gitea/pull/39507 blog.gitea.com: https://blog.gitea.com/release-of-28.1.0/ github.com: https://github.com/go-gitea/gitea/releases/tag/v28.1.0

Credits

๐Ÿ” https://github.com/manus-pi https://github.com/silverwind https://github.com/bircni