CVE-2026-89430: Gitea
High severity, CVSS 8.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created. Each synchronization passed the stored address directly to `git push`, so a name that later resolved to a blocked or internal address was still reached. A user with administrator access to a repository, which includes repositories they create themselves, could aim push mirror synchronization at internal Git services and force-push the repository's contents to them.
Affected products
- Gitea Gitea: up to and including 1.27.3
Published 2026-10-06. Last modified 2026-10-07.