Gitea Patches 27 Security Flaws, Including Critical SSH Authentication Bypass and SSRF
Gitea 28.0.0 and 28.1.0 patch 27 flaws, including a CVSS 9.1 SSH authentication bypass.
Gitea patched 27 reported flaws across 28.0.0 and 28.1.0, with the 28.0.0 notes listing 20 CVEs. CVE-2026-103059 is scored CVSS 9.1: a case-insensitive SQL LIKE lookup on the built-in SSH server could let a crafted RSA key authenticate as another user, including on default SQLite. SSRF and allowlist bypasses, including CVE-2026-70357, CVE-2026-101027, CVE-2026-101029, and push-mirror flaw CVE-2026-89430, could reach internal hosts. Actions approval bypasses and an installer session flaw were also fixed; prior Gitea RCE exploitation involved a different bug.
- Releases 28.0.0 and 28.1.0 address 27 flaws; 28.0.0 lists 20 CVEs.
- CVE-2026-103059 is CVSS 9.1 via case-insensitive SSH public-key matching.
- Migration and push-mirror bugs could reach internal Git hosts.
- Actions flaws let unapproved fork workflows hit self-hosted runners.
- Earlier Gitea RCE exploitation involved a different vulnerability.
Vulnerabilities mentionedAll →
- CVE-2026-942059.8—Unapproved fork workflow execution in Gitea Actionspublished · Gitea+5 related
- CVE-2026-1046328.8—Gitea Actions rerun bypasses fork-PR approvalpublished · Gitea (Actions)
| CVE | Vulnerability | CVSS | EPSS | Flags |
|---|
Full article548 words · extracted from cybersecuritynews.com · click to collapse
Gitea has released security updates addressing 27 reported flaws across versions 28.0.0 and 28.1.0, including a critical SSH authentication bypass and server-side request forgery (SSRF) weaknesses.
The fixes cover account access, repository permissions, automated workflows, and connections to internal systems. Administrators should treat the update as an urgent priority for their development infrastructure.
Released on September 30, Gitea 28.0.0 lists 20 CVEs in its security notes. The reported total of 27 spans that release and the follow-up 28.1.0 update, rather than 28.0.0 alone. Gitea also dropped its historical “1.” version prefix, making this release 28.0.0 instead of 1.28.0.
The standout issue, CVE-2026-103059, carries a CVSS score of 9.1 and affects deployments using Gitea’s built-in SSH server. Its public-key lookup used an SQL LIKE comparison that ignores letter case on some databases, including the default SQLite database. This could cause a specially crafted RSA key to match another user’s registered key.
An attacker who constructs a suitable case variant of a victim’s public key and derives its matching private key could authenticate as that victim.
This is not a general bypass using any altered key; the attacker must meet those key requirements. Gitea now identifies presented keys through their fingerprints, removing the unsafe text comparison.
Gitea Patches 27 Security Flaws
Several patched flaws allowed repository migrations and mirrors to bypass outbound connection rules. CVE-2026-70357 involved a gap between hostname validation and the actual Git connection.
An attacker could change the hostname’s DNS response during that gap, directing Gitea toward an internal host after the initial security check passed.
CVE-2026-101027 allowed an approved domain to skip destination IP checks, while CVE-2026-101029 used multiple DNS answers to bypass the outbound allowlist.
Another flaw, CVE-2026-89430, let push mirrors connect to internal Git hosts after their saved addresses had passed an earlier check, potentially allowing forced pushes.
Gitea now routes Git network operations through an internal proxy that applies outbound access rules when connections occur. Administrators must review configuration changes before upgrading. For a deny-by-default policy, the release notes direct users to set EGRESS_MODE = strict and explicitly list allowed hosts.
The update also closes Gitea Actions approval gaps. CVE-2026-104632 allowed a canceled, approval-pending fork workflow to reach self-hosted runners when rerun.
CVE-2026-94205 checked only the event actor, allowing a maintainer-triggered event to run an untrusted contributor’s workflow without the required approval. Both checks are now tightened.
Other fixes address stored cross-site scripting in container blobs, duplicate Git tree entries that could hide malicious files from reviewers, and an installer flaw that issued an existing administrator’s session without checking the password. Permission fixes also remove lingering repository-transfer access and prevent deploy keys from inheriting repository-owner privileges.
Administrators should back up data, review breaking changes, and upgrade to 28.1.0. Gitea’s release notes explain the new network rules, Git 2.25 minimum, and changed workflow behavior.
Related reporting on private repository permission bypasses provides useful background on Gitea access risks. Previous coverage of Gitea RCE exploitation also shows why delayed patching matters. However, those attacks involved a separate vulnerability, not these newly fixed issues.
Stops threats before impact with a 21-minute faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.