CVE-2026-95106: Gitea review and execution mismatch through duplicate tree entries
Gitea accepted pushed Git trees containing two entries with the same name, which Git's own consistency checks reject. Gitea's web views resolved such a path to the first entry, while git checkout, Gitea Actions, and release archives use the last. A contributor could open a pull request whose diff and file views show benign content while CI and checkouts at the same commit use different, attacker-controlled content. Incoming objects are now checked for consistency; objects already stored in existing repositories are not rescanned.
Affected Software
Event History
Frequently Asked Questions
Which repositories face the most immediate risk?
Repositories that accept contributions from parties who can push commits or open pull requests are exposed to review bypass risk. A malicious contributor can make the web review show one file entry while CI, checkouts, and release archives use another entry at the same path.
What must an attacker be able to do?
The attacker needs to introduce a Git tree containing duplicate entries with the same name into the repository, such as through a contributed commit or pull request. The mismatch matters when reviewers rely on Gitea web views but automation or users consume the checked-out commit.
Are repositories with existing data automatically cleaned up by the new checks?
No. Incoming objects are checked for consistency, but objects already stored in existing repositories are not rescanned.
How can teams assess whether historical content may still be affected?
The provided information does not identify a built-in rescan or detection process for existing repositories. Teams should account for the fact that pre-existing stored objects are outside the new incoming-object consistency checks.