CVE-2026-89430
Gitea push mirror SSRF and forced writes to internal Git hosts
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created. Each synchronization passed the stored address directly to `git push`, so a name that later resolved to a blocked or internal address was still reached. A user with administrator access to a repository, which includes repositories they create themselves, could aim push mirror synchronization at internal Git services and force-push the repository's contents to them.
| CWE | CWE-367 CWE-918 |
| Vendor | gitea |
| Product | gitea |
| Published | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for gitea gitea
Be the first to know when new unknown vulnerabilities affecting gitea gitea are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Gitea / Gitea
0 โค 1.27.3
References
github.com: https://github.com/go-gitea/gitea/security/advisories/GHSA-hcgw-r9gf-8mph github.com: https://github.com/go-gitea/gitea/pull/39010 github.com: https://github.com/go-gitea/gitea/pull/39426 blog.gitea.com: https://blog.gitea.com/release-of-28.0.0/ github.com: https://github.com/go-gitea/gitea/releases/tag/v28.0.0
Credits
๐ https://github.com/thesmartshadow ๐ https://github.com/manus-use ๐ https://github.com/cy3erm https://github.com/TheFox0x7 https://github.com/silverwind https://github.com/bircni https://github.com/wxiaoguang