CVE-2026-89430: Gitea push mirror SSRF and forced writes to internal Git hosts

Published Oct 6, 2026
·
Updated

Gitea validated a push mirror's remote address against the [migrations] allow and block lists only when the mirror was created. Each synchronization passed the stored address directly to git push, so a name that later resolved to a blocked or internal address was still reached. A user with administrator access to a repository, which includes repositories they create themselves, could aim push mirror synchronization at internal Git services and force-push the repository's contents to them.

Affected Software

1 affected component
Gitea Gitea

Event History

Oct 6, 2026
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs administrator access to a repository. This includes users who can create their own repositories and therefore have administrator access to them.

2

What access does the vulnerable instance need for exploitation to have impact?

The Gitea server must be able to reach the targeted internal Git service. The issue can then be used to direct push mirror synchronization to that service and force-push repository contents.

3

Are the migration allow and block lists sufficient protection?

No. They were checked when a push mirror was created, but not during later synchronizations. A previously allowed hostname that later resolves to a blocked or internal address can still be reached during synchronization.

4

How could an administrator identify potentially affected mirrors?

Review existing push mirrors, particularly those using hostnames whose DNS resolution may have changed after mirror creation. Mirrors targeting names that now resolve to internal or blocked addresses are relevant.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203