AI analysis
Gitea validates a push mirror's remote address against the [migrations] allow and block lists only when the mirror is created. Each later synchronization passes the stored address directly to git push, so a name that subsequently resolves to a blocked or internal address is still reached (a time-of-check/time-of-use gap that enables server-side request forgery). A user with administrator access to a repository—including any repository they create—can aim push-mirror sync at internal Git services and force-push that repository's contents to them, with high impact to confidentiality and integrity. Self-hosted Gitea deployments that use push mirrors are in scope; affected version ranges are not stated in the advisory data. No public proof of concept is known, and the issue is not listed in CISA KEV.
What to do: No fixed version is named in this advisory, so upgrade Gitea as soon as the vendor ships a release that re-checks push-mirror remotes on every sync, and do not rely on creation-time migration allow/block lists alone. Until then, restrict who can administer repositories, audit existing push mirrors for hostnames that could later resolve internally, and block egress from the Gitea host to internal Git services.
Estimated exposure
large≈10,000–100,000 internet-facing Gitea instances, plus additional private deployments (version-specific count unknown) — Order-of-magnitude figure from typical public internet-scan counts of self-hosted Gitea; the advisory gives no affected version range, so the share still running a vulnerable build is unknown.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created. Each synchronization passed the stored address directly to `git push`, so a name that later resolved to a blocked or internal address was still reached. A user with administrator access to a repository, which includes repositories they create themselves, could aim push mirror synchronization at internal Git services and force-push the repository's contents to them.