Back Gbhackers Critical Gitea Vulnerabilities Allow Attackers to Bypass Authentication and Execute Code
Gitea has released version 28.0.0, addressing 20 vulnerabilities related to authentication bypass, unauthorized workflow execution, server-side request forgery, stored cross-site scripting, and denial of service.
Announced on September 30, 2026 , this release removes the historical “1.” version prefix. Maintainers have urged administrators to upgrade promptly to mitigate vulnerabilities affecting repository access, automation, and outbound connections.
The most significant issues involve account impersonation and running untrusted workflows on self-hosted runners. These attack paths are distinct: authentication weaknesses compromise account access, while approval bypasses for Actions expose runner infrastructure to code controlled by contributors. The announcement does not describe a single unauthenticated server-takeover chain or provide CVSS scores.
Critical Gitea Vulnerabilities
CVE-2026-103059 affects Gitea’s built-in SSH server, which previously used a case-insensitive SQL LIKE operation to match public keys. This vulnerability allowed a forged case-variant RSA key to match another user’s account. The update replaces this lookup with fingerprint-based identification, correcting how it associates accounts.
A separate installer vulnerability, CVE-2026-96404, allowed re-running the installation against an existing database to create a session for an existing administrator without verifying that account’s password. Databases containing only one user bypassed the confirmation requirement for reinstallation.
This release fixes these installer behaviors, although exploitation depends on the installation pathway being accessible under specific deployment conditions.
In Gitea Actions, CVE-2026-104632 allowed cancellation and rerunning of an approval-pending pull request workflow, letting jobs run while approval was still outstanding.
This meant that a first-time contributor’s code could run on self-hosted runners without prior approval. The updated version now requires explicit approval recording and identifies the approver.
CVE-2026-94205 revealed another approval bypass, as checks only considered the event initiator. As a result, a maintainer-triggered pull request event could execute the workflow of an untrusted fork.
Gitea now verifies both the event actor and pull request author. Related fixes prevent approval from reviving canceled jobs and stop unapproved workflows from canceling trusted concurrent runs.
Several vulnerabilities compromised outbound network restrictions. CVE-2026-70357 split migration hostname validation from the subsequent Git connection, enabling DNS rebinding to access internal hosts. CVE-2026-101027 bypassed destination IP checks for allowed domains, while CVE-2026-101029 exploited multiple DNS answers to permit internal reads and writes.
Push mirrors and Git HTTP redirects also presented additional policy bypasses. Gitea now routes Git network operations through an internal proxy that enforces egress restrictions during connections, rather than relying solely on earlier hostname checks.
CVE-2026-95106 allowed duplicate Git tree entry names to hide malicious content, making reviewed files differ from those in checkout and continuous integration (CI) content.
Incoming pushes and transfers now undergo Git object consistency checks. Additionally, CVE-2026-103667 enabled stored cross-site scripting (XSS) through attacker-controlled container blob content types; blobs now use the application/octet-stream content type.
Administrators should review breaking changes, back up their data, replace the binary or container, and restart the service. Git version 2.25.0 or newer is required. Particular attention should be paid to outbound policies: strict mode provides a deny-by-default behavior, and deprecated migration settings have new replacements.
The release also imposes a limit on workflow matrices, rejecting those that exceed 256 combinations before expansion, thus addressing potential memory exhaustion.
Additional patches resolve lingering issues related to repository-transfer access, deploy-key permission bypasses, stale team permissions, and denial-of-service vulnerabilities in issue parsing.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC .
Artificial Intelligence
Cyber security Course
Cyber Security Resources
Cybersecurity
Information Gathering
Information Security Risks
Critical Cisco Nexus Switch Vulnerabilities Allow Unauthenticated Attackers to Execute Code as Root
Financially Motivated Hacker Uses Agentic AI to Breach Multiple South Korean Finance Targets
PoC Exploit Released for Critical VMware Vulnerability Enabling Guest-to-Host Attacks
Hackers Target Hotels With Fake Guest Complaints to Deploy Blockchain-Based RAT Malware
Critical Splunk Enterprise Vulnerability Lets Unauthenticated Attackers Execute OS Commands
ChainDrop and PolinRider Use Blockchain C2 to Steal Cloud and CI/CD Credentials
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
