TL;DR
Gitea has shipped 27 security fixes across versions 28.0.0 and 28.1.0. This Gitea security update closes server-side request forgery (SSRF) paths, an installer bug that grants admin sessions without a password, and several Gitea Actions approval bypasses. Admins should upgrade to Gitea 28.1.0.
- Total: 27 CVEs
- Severity: 4 Critical · 13 High · 10 Medium
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-94205
- Action: Apply the latest security updates now
Turn matching CVEs into GitHub Issues automatically — no copy-pasting, no duplicates.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-94205 | 9.8 | CWE-441 | Not exploited |
| CVE-2026-103059 | 9.1 | CWE-305 | Not exploited |
| CVE-2026-95106 | 9.1 | CWE-706 | Not exploited |
| CVE-2026-101023 | 9.1 | CWE-287 | Not exploited |
| CVE-2026-104632 | 8.8 | CWE-285 | Not exploited |
| CVE-2026-104626 | 8.8 | CWE-841 | Not exploited |
| CVE-2026-89430 | 8.1 | CWE-367 | Not exploited |
| CVE-2026-96404 | 8.1 | CWE-287 | Not exploited |
Why It Matters
Gitea is a popular self-hosted Git service. Teams use it to store source code, run CI pipelines and host container images. As a result, a flaw in Gitea can reach far beyond one repository.
Most of these bugs need a logged-in user or a specific setting. Even so, many instances allow open sign-ups or fork pull requests. The advisories list the exploitation status as unknown, and no public proof-of-concept has been confirmed.
How the Attacks Work
SSRF Through Migrations and Mirrors
Six flaws let users steer the Gitea server toward internal systems. The highest rated is CVE-2026-101027, scored 7.7 on CVSS. Gitea accepted a hostname on its migration allow list “without checking its resolved address against the local-network restrictions.” Related bugs abused DNS changes, multiple DNS answers and HTTP redirects to slip past the same checks.
Account and Admin Takeover
CVE-2026-96404 affects the web installer when it is reachable against an existing database. Submitting a matching admin username “issued an authenticated session for that account without verifying its password.” Meanwhile, CVE-2026-103059 hits the built-in SSH server. A case-insensitive key lookup on databases such as SQLite could match an attacker’s crafted key to another user.
Gitea Actions Approval Bypasses
Four bugs let code from fork pull requests reach a project’s runners without proper approval. For example, routine triage such as adding a label could start a fork run with no sign-off. Another flaw let a tiny workflow matrix explode into a huge number of jobs and crash the server.
Other Notable Fixes
CVE-2026-95106 let a contributor show reviewers benign code while CI built different content at the same commit. Two XSS bugs abused the container registry and a media API to run scripts on the Gitea origin. This Gitea security update also closes a privacy gap, CVE-2026-96589. A rejected repository transfer left the recipient with lasting read access to a private repository. In addition, the 28.1.0 release fixes an OAuth2 flaw that let access tokens be swapped for fresh tokens.
Affected Versions
- 19 flaws affect Gitea 1.27.3 and earlier and are fixed in 28.0.0.
- 8 more affect releases up to 28.0.0 and are fixed in 28.1.0.
Several bugs only apply to non-default settings, such as a custom migration allow list or the built-in SSH server.
Patch and Mitigation Steps
Upgrade straight to Gitea 28.1.0, since 28.0.0 still carries eight of these issues. Details on the first batch sit in the Gitea 28.0.0 release notes.
Until you upgrade, keep the web installer locked and limit who can create migrations and mirrors. Also require approval for fork pull request workflows, and review recent Actions runs. Taken together, these steps reduce risk while the Gitea security update rolls out.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!