AI analysis
Gitea accepted pushed Git trees that contain two entries with the same name, which Git’s own consistency checks would reject. Its web views resolved that path to the first entry, while git checkout, Gitea Actions, and release archives used the last entry. A contributor who can open a pull request can therefore show reviewers a benign diff and file view while CI, checkouts, and release archives at the same commit use different attacker-controlled content, compromising integrity and confidentiality of what is built or shipped. Instances that accept pushes or pull requests are affected; the advisory does not name a version range. There is no known public proof of concept and the flaw is not listed in CISA KEV. Incoming objects are now checked for consistency, but objects already stored in existing repositories are not rescanned.
What to do: Upgrade Gitea to a release that rejects inconsistent incoming Git objects (duplicate tree names). Because objects already stored in existing repositories are not rescanned, audit current repos and pull requests for trees with duplicate path entries, and treat checkouts, Actions runs, and release archives of suspect commits as untrusted until re-verified.
Estimated exposure
largeOn the order of 10,000–100,000 internet-exposed instances, plus further private deployments — Estimate from Gitea’s wide use as a self-hosted Git forge and public internet-scan ranges that have typically shown tens of thousands of exposed instances, plus additional private deployments; no install count is in the CVE data.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Gitea accepted pushed Git trees containing two entries with the same name, which Git's own consistency checks reject. Gitea's web views resolved such a path to the first entry, while `git checkout`, Gitea Actions, and release archives use the last. A contributor could open a pull request whose diff and file views show benign content while CI and checkouts at the same commit use different, attacker-controlled content. Incoming objects are now checked for consistency; objects already stored in existing repositories are not rescanned.