Cyber Security News

Critical Gitea Vulnerabilities Allow Attackers to Bypass Authentication and Execute Code

Gitea has released version 28.0.0, addressing 20 vulnerabilities related to authentication bypass, unauthorized workflow execution, server-side request forgery, stored cross-site scripting, and denial of service.

Announced on September 30, 2026, this release removes the historical “1.” version prefix. Maintainers have urged administrators to upgrade promptly to mitigate vulnerabilities affecting repository access, automation, and outbound connections.

The most significant issues involve account impersonation and running untrusted workflows on self-hosted runners. These attack paths are distinct: authentication weaknesses compromise account access, while approval bypasses for Actions expose runner infrastructure to code controlled by contributors. The announcement does not describe a single unauthenticated server-takeover chain or provide CVSS scores.

Critical Gitea Vulnerabilities

CVE-2026-103059 affects Gitea’s built-in SSH server, which previously used a case-insensitive SQL LIKE operation to match public keys. This vulnerability allowed a forged case-variant RSA key to match another user’s account. The update replaces this lookup with fingerprint-based identification, correcting how it associates accounts.

A separate installer vulnerability, CVE-2026-96404, allowed re-running the installation against an existing database to create a session for an existing administrator without verifying that account’s password. Databases containing only one user bypassed the confirmation requirement for reinstallation.

This release fixes these installer behaviors, although exploitation depends on the installation pathway being accessible under specific deployment conditions.

In Gitea Actions, CVE-2026-104632 allowed cancellation and rerunning of an approval-pending pull request workflow, letting jobs run while approval was still outstanding.

This meant that a first-time contributor’s code could run on self-hosted runners without prior approval. The updated version now requires explicit approval recording and identifies the approver.

CVE-2026-94205 revealed another approval bypass, as checks only considered the event initiator. As a result, a maintainer-triggered pull request event could execute the workflow of an untrusted fork.

Gitea now verifies both the event actor and pull request author. Related fixes prevent approval from reviving canceled jobs and stop unapproved workflows from canceling trusted concurrent runs.

Several vulnerabilities compromised outbound network restrictions. CVE-2026-70357 split migration hostname validation from the subsequent Git connection, enabling DNS rebinding to access internal hosts. CVE-2026-101027 bypassed destination IP checks for allowed domains, while CVE-2026-101029 exploited multiple DNS answers to permit internal reads and writes.

Push mirrors and Git HTTP redirects also presented additional policy bypasses. Gitea now routes Git network operations through an internal proxy that enforces egress restrictions during connections, rather than relying solely on earlier hostname checks.

CVE-2026-95106 allowed duplicate Git tree entry names to hide malicious content, making reviewed files differ from those in checkout and continuous integration (CI) content.

Incoming pushes and transfers now undergo Git object consistency checks. Additionally, CVE-2026-103667 enabled stored cross-site scripting (XSS) through attacker-controlled container blob content types; blobs now use the application/octet-stream content type.

Administrators should review breaking changes, back up their data, replace the binary or container, and restart the service. Git version 2.25.0 or newer is required. Particular attention should be paid to outbound policies: strict mode provides a deny-by-default behavior, and deprecated migration settings have new replacements.

The release also imposes a limit on workflow matrices, rejecting those that exceed 256 combinations before expansion, thus addressing potential memory exhaustion.

Additional patches resolve lingering issues related to repository-transfer access, deploy-key permission bypasses, stale team permissions, and denial-of-service vulnerabilities in issue parsing.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

3 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago