CVE-2026-95106: Gitea review and execution mismatch through duplicate tree entries

Published Oct 6, 2026
·
Updated

Gitea accepted pushed Git trees containing two entries with the same name, which Git's own consistency checks reject. Gitea's web views resolved such a path to the first entry, while git checkout, Gitea Actions, and release archives use the last. A contributor could open a pull request whose diff and file views show benign content while CI and checkouts at the same commit use different, attacker-controlled content. Incoming objects are now checked for consistency; objects already stored in existing repositories are not rescanned.

Affected Software

1 affected component
Gitea Gitea

Event History

Oct 6, 2026
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
Description
Data Sourced
via NVD·08:17 PM
Description

Frequently Asked Questions

1

Which repositories face the most immediate risk?

Repositories that accept contributions from parties who can push commits or open pull requests are exposed to review bypass risk. A malicious contributor can make the web review show one file entry while CI, checkouts, and release archives use another entry at the same path.

2

What must an attacker be able to do?

The attacker needs to introduce a Git tree containing duplicate entries with the same name into the repository, such as through a contributed commit or pull request. The mismatch matters when reviewers rely on Gitea web views but automation or users consume the checked-out commit.

3

Are repositories with existing data automatically cleaned up by the new checks?

No. Incoming objects are checked for consistency, but objects already stored in existing repositories are not rescanned.

4

How can teams assess whether historical content may still be affected?

The provided information does not identify a built-in rescan or detection process for existing repositories. Teams should account for the fact that pre-existing stored objects are outside the new incoming-object consistency checks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203