Vulnerability
Published 2026-10-06
Verified 2026-10-08

Gitea 28.0.0 and 28.1.0 fix 29 CVEs, including a built-in SSH server key mix-up that can let a crafted RSA key log in as another user (CVE-2026-103059, CVSS 9.1 as reported), SSRF bypasses in mirrors and migrations, and Actions approval gaps

Gitea released 28.0.0 on 30 September 2026 (the project has dropped the old '1.' prefix) with 20 security fixes, then 28.1.0 on 6 October with nine more. The most serious, CVE-2026-103059 (CVSS 9.1 as reported by Cyber Security News), affects instances using Gitea's built-in SSH server: public keys were looked up with a case-insensitive SQL LIKE, so a forged case-variant RSA key whose private key the attacker controls could be matched to another user's account. Keys are now matched by fingerprint. Other 28.0.0 fixes close several ways for repository migrations, mirrors and push mirrors to reach internal hosts despite the outbound allowlist (DNS rebinding, multiple DNS answers and approved-domain IP skips, including CVE-2026-70357, CVE-2026-101027, CVE-2026-101029 and CVE-2026-89430); Gitea now sends Git network traffic through an internal proxy that enforces the rules at connect time. Gitea Actions fixes stop cancelled-then-rerun fork pull request runs from reaching self-hosted runners without approval (CVE-2026-104632, CVE-2026-104626) and stop a maintainer's event from running an untrusted contributor's workflow (CVE-2026-94205). There are also stored XSS fixes (container registry blobs, CVE-2026-103667) and a duplicate Git tree entry check that hid files from review (CVE-2026-95106). 28.1.0 adds fixes for push mirror API permission checks (CVE-2026-97208, CVE-2026-86684), repository media stored XSS (CVE-2026-96594) and an OAuth2 refresh grant that accepted access tokens (CVE-2026-101023). No exploitation is reported. Upgrading changes egress settings (set EGRESS_MODE = strict for deny-by-default) and needs Git 2.25 or later, so read the release notes first. Primary: Gitea blog; wire: Cyber Security News.

Product
Gitea (self-hosted Git service)
Versions
1.27.x and earlier (fixed across 28.0.0 and 28.1.0); CVE-2026-103059 only where the built-in SSH server is used
CVSS
9.1 (CVE-2026-103059, as reported by Cyber Security News); others not stated by Gitea
Exploited in Australia?
unknown
Patch to
Gitea 28.1.0. Back up first, review the new egress settings and Git 2.25 minimum, and re-check self-hosted Actions runner approval settings after upgrading.

Primary: Gitea blog — Gitea 28.1.0 is released (6 Oct 2026) · Vendor: Gitea blog — Gitea 28.0.0 is released (30 Sep 2026) · CVE: CVE-2026-103059, CVE-2026-70357, CVE-2026-101027, CVE-2026-101029, CVE-2026-89430, CVE-2026-104632, CVE-2026-104626, CVE-2026-94205, CVE-2026-103667, CVE-2026-95106, CVE-2026-97208, CVE-2026-86684, CVE-2026-96594, CVE-2026-101023 · Cyber Security News — Gitea patches security flaws including critical SSH authentication bypass and SSRF (8 Oct 2026)

vulnerabilities identity cloud