CVE-2026-97208: Gitea push mirror API bypass of DISABLE_NEW_PUSH policy
The Gitea API endpoint for creating push mirrors (POST /api/v1/repos/{owner}/{repo}/pushmirrors) checked only whether mirroring was enabled and not the [mirror] DISABLENEWPUSH setting that the web interface enforces. A repository administrator could therefore create new push mirrors on instances where the site administrator had disabled them. A push mirror pushes all refs of the repository to a remote chosen by the caller, on each commit or on a schedule.
Affected Software
Event History
Frequently Asked Questions
Who can use the affected API capability?
A repository administrator can create a new push mirror through the API when mirroring is enabled, even if the site administrator has disabled new push mirrors through the DISABLE_NEW_PUSH setting.
What can be sent to a remote created this way?
A push mirror sends all repository refs to a remote selected by the caller. It pushes on each commit or according to its configured schedule.