2026-10-06 21:36CVE-2026-89182Gitea
PUBLISHED5.2CWE-863

Gitea push-to-create bypass of FORCE_PRIVATE policy

With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The default configuration is not affected.

Problem type

Affected products

Gitea

Gitea

<= 28.0.0 - AFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-89182
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-89182",
    "assignerOrgId": "88ee5874-cf24-4952-aea0-31affedb7ff2",
    "assignerShortName": "Gitea",
    "dateUpdated": "2026-10-06T21:36:01.187Z",
    "dateReserved": "2026-10-04T22:02:04.881Z",
    "datePublished": "2026-10-06T21:36:01.187Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "88ee5874-cf24-4952-aea0-31affedb7ff2",
        "shortName": "Gitea",
        "dateUpdated": "2026-10-06T21:36:01.187Z"
      },
      "title": "Gitea push-to-create bypass of FORCE_PRIVATE policy",
      "descriptions": [
        {
          "lang": "en",
          "value": "With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The default configuration is not affected."
        }
      ],
      "affected": [
        {
          "vendor": "Gitea",
          "product": "Gitea",
          "packageName": "gitea.dev",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "1.27.0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "28.0.0"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-863: Incorrect Authorization",
              "cweId": "CWE-863",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-fx95-gwfc-grgc",
          "name": "GitHub Security Advisory GHSA-fx95-gwfc-grgc",
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/39501",
          "name": "Fix: go-gitea/gitea pull request #39501",
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/pull/39507",
          "name": "Fix backport to release/v28: go-gitea/gitea pull request #39507",
          "tags": [
            "patch"
          ]
        },
        {
          "url": "https://blog.gitea.com/release-of-28.1.0/",
          "name": "Gitea 28.1.0 release announcement",
          "tags": [
            "release-notes"
          ]
        },
        {
          "url": "https://github.com/go-gitea/gitea/releases/tag/v28.1.0",
          "name": "go-gitea/gitea v28.1.0 release",
          "tags": [
            "release-notes"
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "https://github.com/manus-pi",
          "type": "reporter"
        },
        {
          "lang": "en",
          "value": "https://github.com/silverwind",
          "type": "remediation developer"
        },
        {
          "lang": "en",
          "value": "https://github.com/bircni",
          "type": "remediation developer"
        }
      ]
    }
  }
}