5.4
CVE-2026-89182
- EPSS 0.18%
- Veröffentlicht 06.10.2026 21:36:01
- Zuletzt bearbeitet 07.10.2026 13:45:36
- Erkennungen
Gitea push-to-create bypass of FORCE_PRIVATE policy
With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The default configuration is not affected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGitea
≫
Produkt
Gitea
Default Statusunaffected
Version <=
28.0.0
Version
1.27.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.067 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://github.com/go-gitea/gitea/pull/39501
https://github.com/go-gitea/gitea/pull/39507
https://blog.gitea.com/release-of-28.1.0/
https://github.com/go-gitea/gitea/releases/tag/v28.1.0
https://github.com/go-gitea/gitea/security/advisories/GHSA-fx95-gwfc-grgc