PT-2026-107290 · Gitea · Gitea

CVE-2026-97208

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Gitea (affected versions not specified)
Description The API endpoint POST /api/v1/repos/{owner}/{repo}/push mirrors fails to verify the [mirror] DISABLE NEW PUSH configuration setting, which is otherwise enforced by the web interface. This allows a repository administrator to create new push mirrors even when the site administrator has disabled this functionality. A push mirror is a feature that automatically pushes all repository references to a remote destination selected by the user, triggered by commits or a predefined schedule.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97208
GHSA-8HHH-MQPG-JPXC

Affected Products

Gitea