Critical Gitea Vulnerabilities Allow Attackers to Bypass Authentication and Execute Code
Gitea 28.0.0 patches 20 flaws, including SSH impersonation, workflow approval bypasses, and SSRF.
Gitea released version 28.0.0 on September 30, 2026, patching 20 vulnerabilities and dropping the historical "1." version prefix. CVE-2026-103059 allowed a forged case-variant RSA public key to match another account on the built-in SSH server. Installer flaw CVE-2026-96404 could mint an administrator session without a password check, while CVE-2026-104632 and CVE-2026-94205 let untrusted Actions workflows run on self-hosted runners before approval. Further fixes cover DNS-rebinding SSRF, stored XSS in container blobs, and hidden malicious Git tree entries; no CVSS scores or active exploitation are reported.
- Gitea 28.0.0 fixes 20 flaws and drops the 1. version prefix.
- CVE-2026-103059 let a case-variant RSA key impersonate another SSH user.
- Actions bypasses could run untrusted fork workflows on self-hosted runners.
- SSRF and DNS rebinding bypassed outbound migration and mirror restrictions.
- No CVSS scores or active exploitation are reported.
Vulnerabilities mentionedAll →
- CVE-2026-942059.8—Unapproved fork workflow execution in Gitea Actionspublished · Gitea+7 related
- CVE-2026-1046328.8—Gitea Actions rerun bypasses fork-PR approvalpublished · Gitea (Actions)
| CVE | Vulnerability | CVSS | EPSS | Flags |
|---|
Full article574 words · extracted from gbhackers.com · click to collapse
Gitea has released version 28.0.0, addressing 20 vulnerabilities related to authentication bypass, unauthorized workflow execution, server-side request forgery, stored cross-site scripting, and denial of service.
Announced on September 30, 2026, this release removes the historical “1.” version prefix. Maintainers have urged administrators to upgrade promptly to mitigate vulnerabilities affecting repository access, automation, and outbound connections.
The most significant issues involve account impersonation and running untrusted workflows on self-hosted runners. These attack paths are distinct: authentication weaknesses compromise account access, while approval bypasses for Actions expose runner infrastructure to code controlled by contributors. The announcement does not describe a single unauthenticated server-takeover chain or provide CVSS scores.
Critical Gitea Vulnerabilities
CVE-2026-103059 affects Gitea’s built-in SSH server, which previously used a case-insensitive SQL LIKE operation to match public keys. This vulnerability allowed a forged case-variant RSA key to match another user’s account. The update replaces this lookup with fingerprint-based identification, correcting how it associates accounts.
A separate installer vulnerability, CVE-2026-96404, allowed re-running the installation against an existing database to create a session for an existing administrator without verifying that account’s password. Databases containing only one user bypassed the confirmation requirement for reinstallation.
This release fixes these installer behaviors, although exploitation depends on the installation pathway being accessible under specific deployment conditions.
In Gitea Actions, CVE-2026-104632 allowed cancellation and rerunning of an approval-pending pull request workflow, letting jobs run while approval was still outstanding.
This meant that a first-time contributor’s code could run on self-hosted runners without prior approval. The updated version now requires explicit approval recording and identifies the approver.
CVE-2026-94205 revealed another approval bypass, as checks only considered the event initiator. As a result, a maintainer-triggered pull request event could execute the workflow of an untrusted fork.
Gitea now verifies both the event actor and pull request author. Related fixes prevent approval from reviving canceled jobs and stop unapproved workflows from canceling trusted concurrent runs.
Several vulnerabilities compromised outbound network restrictions. CVE-2026-70357 split migration hostname validation from the subsequent Git connection, enabling DNS rebinding to access internal hosts. CVE-2026-101027 bypassed destination IP checks for allowed domains, while CVE-2026-101029 exploited multiple DNS answers to permit internal reads and writes.
Push mirrors and Git HTTP redirects also presented additional policy bypasses. Gitea now routes Git network operations through an internal proxy that enforces egress restrictions during connections, rather than relying solely on earlier hostname checks.
CVE-2026-95106 allowed duplicate Git tree entry names to hide malicious content, making reviewed files differ from those in checkout and continuous integration (CI) content.
Incoming pushes and transfers now undergo Git object consistency checks. Additionally, CVE-2026-103667 enabled stored cross-site scripting (XSS) through attacker-controlled container blob content types; blobs now use the application/octet-stream content type.
Administrators should review breaking changes, back up their data, replace the binary or container, and restart the service. Git version 2.25.0 or newer is required. Particular attention should be paid to outbound policies: strict mode provides a deny-by-default behavior, and deprecated migration settings have new replacements.
The release also imposes a limit on workflow matrices, rejecting those that exceed 256 combinations before expansion, thus addressing potential memory exhaustion.
Additional patches resolve lingering issues related to repository-transfer access, deploy-key permission bypasses, stale team permissions, and denial-of-service vulnerabilities in issue parsing.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.