๐Ÿ” CVE Alert

CVE-2026-89430

UNKNOWN 0.0

Gitea push mirror SSRF and forced writes to internal Git hosts

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created. Each synchronization passed the stored address directly to `git push`, so a name that later resolved to a blocked or internal address was still reached. A user with administrator access to a repository, which includes repositories they create themselves, could aim push mirror synchronization at internal Git services and force-push the repository's contents to them.

CWE CWE-367 CWE-918
Vendor gitea
Product gitea
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for gitea gitea

Be the first to know when new unknown vulnerabilities affecting gitea gitea are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Gitea / Gitea
0 โ‰ค 1.27.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/go-gitea/gitea/security/advisories/GHSA-hcgw-r9gf-8mph github.com: https://github.com/go-gitea/gitea/pull/39010 github.com: https://github.com/go-gitea/gitea/pull/39426 blog.gitea.com: https://blog.gitea.com/release-of-28.0.0/ github.com: https://github.com/go-gitea/gitea/releases/tag/v28.0.0

Credits

๐Ÿ” https://github.com/thesmartshadow ๐Ÿ” https://github.com/manus-use ๐Ÿ” https://github.com/cy3erm https://github.com/TheFox0x7 https://github.com/silverwind https://github.com/bircni https://github.com/wxiaoguang