UNKNOWN NVD
CVE-2026-89430
Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created. Each synchronization passed th
Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created. Each synchronization passed the stored address directly to `git push`, so a name that later resolved to a blocked or internal address was still reached. A user with administrator access to a repository, which includes repositories they create themselves, could aim push mirror synchronization at internal Git services and force-push the repository's contents to them.
References
- https://blog.gitea.com/release-of-28.0.0/
- https://github.com/go-gitea/gitea/pull/39010
- https://github.com/go-gitea/gitea/pull/39426
- https://github.com/go-gitea/gitea/releases/tag/v28.0.0
- https://github.com/go-gitea/gitea/security/advisories/GHSA-hcgw-r9gf-8mph
This unknown severity vulnerability was published on 2026-10-06 via NVD.
vulnfeed aggregates 9512 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.