Critical Gitea Vulnerabilities Allow Attackers to Bypass Authentication and Execute Code
Gitea 28.0.0 patches 20 flaws, including SSH impersonation, workflow approval bypasses, and SSRF.
Gitea released version 28.0.0 on September 30, 2026, patching 20 vulnerabilities and dropping the historical "1." version prefix. CVE-2026-103059 allowed a forged case-variant RSA public key to match another account on the built-in SSH server. Installer flaw CVE-2026-96404 could mint an administrator session without a password check, while CVE-2026-104632 and CVE-2026-94205 let untrusted Actions workflows run on self-hosted runners before approval. Further fixes cover DNS-rebinding SSRF, stored XSS in container blobs, and hidden malicious Git tree entries; no CVSS scores or active exploitation are reported.