Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
AI-Powered Attacks Breach South Korean Financial Firms, Steal Data
October 8, 2026
Gitea Patches Critical SSH Auth Bypass, SSRF, and 25 Other Flaws
October 8, 2026
Microsoft Teams Phishing Scam Steals Credentials with Fake Login Page
October 8, 2026
Home/CyberSecurity News/Gitea Patches Critical SSH Auth Bypass, SSRF, and 25 Other Flaws
CyberSecurity News

Gitea Patches Critical SSH Auth Bypass, SSRF, and 25 Other Flaws

Key Takeaways Gitea released urgent security updates for versions 28.0.0 and 28.1.0, addressing a total of 27 vulnerabilities. The most critical flaw, CVE-2026-103059, is an SSH authentication bypass...

Sarah simpson
Sarah simpson
October 8, 2026 4 Min Read
3 0

Key Takeaways

  • Gitea released urgent security updates for versions 28.0.0 and 28.1.0, addressing a total of 27 vulnerabilities.
  • The most critical flaw, CVE-2026-103059, is an SSH authentication bypass with a CVSS score of 9.1, affecting Gitea’s built-in SSH server.
  • Multiple Server-Side Request Forgery (SSRF) vulnerabilities were also patched, allowing attackers to potentially access internal networks.
  • Administrators are advised to prioritize upgrading to Gitea 28.1.0 immediately and review new egress configuration requirements.

Gitea Addresses Critical SSH Bypass and 26 Other Flaws

Gitea, the popular self-hosted Git service, has rolled out a comprehensive security update, patching 27 distinct vulnerabilities across its recent 28.0.0 and 28.1.0 releases. The patches tackle critical issues, including an SSH authentication bypass and multiple server-side request forgery (SSRF) weaknesses, which could allow unauthorized access and internal network probing.

Table Of Content

  • Key Takeaways
  • Gitea Addresses Critical SSH Bypass and 26 Other Flaws
  • Critical SSH Authentication Bypass
  • SSRFS and Outbound Connection Vulnerabilities
  • Gitea Actions and Other Security Enhancements
  • What You Should Do

These fixes are crucial for the integrity of account access, repository permissions, automated workflows, and the security of connections to internal systems. System administrators managing Gitea installations are strongly urged to prioritize these updates to safeguard their development infrastructure.

The initial Gitea 28.0.0 release, dated September 30, introduced 20 CVEs, with the subsequent 28.1.0 update expanding the total count of addressed vulnerabilities to 27. Notably, Gitea also transitioned its version numbering scheme, dropping the “1.” prefix, making this release 28.0.0 instead of the previous 1.28.0 format.

Critical SSH Authentication Bypass

Among the patched flaws, CVE-2026-103059 stands out with a high CVSS score of 9.1. This critical vulnerability impacts Gitea deployments utilizing its integrated SSH server. The flaw stemmed from an SQL LIKE comparison used during public-key lookups, which, on certain databases like the default SQLite, ignored letter casing. This oversight meant that a meticulously crafted RSA key could be made to match another legitimate user’s registered public key.

An attacker capable of generating a case-variant of a victim’s public key and subsequently deriving its corresponding private key could then authenticate as the victim. It is important to note that this is not a generic bypass; it specifically requires the attacker to meet these precise key generation criteria. Gitea has mitigated this by shifting to identifying presented keys via their unique fingerprints, thereby eliminating the insecure text-based comparison.

SSRFS and Outbound Connection Vulnerabilities

Several other significant vulnerabilities addressed in the update involved server-side request forgery (SSRF) and issues with outbound connection rules. CVE-2026-70357, for instance, exploited a timing window between hostname validation and the actual Git connection during repository migrations and mirrors. An attacker could manipulate the hostname’s DNS response in this gap, redirecting Gitea to an internal network host after the initial security check had been successfully bypassed.

Further SSRF-related flaws include CVE-2026-101027, which permitted an approved domain to bypass destination IP verification, and CVE-2026-101029, which leveraged multiple DNS answers to circumvent outbound allowlists. Additionally, CVE-2026-89430 allowed push mirrors to connect to internal Git hosts even after their saved addresses had passed an earlier security check, potentially enabling forced pushes to sensitive repositories.

To address these network-related bypasses, Gitea now routes all Git network operations through an internal proxy designed to enforce outbound access rules at the point of connection. Administrators must review new configuration settings before upgrading. For environments requiring a deny-by-default policy, Gitea’s release notes instruct users to set EGRESS_MODE = strict and explicitly whitelist permitted hosts.

Gitea Actions and Other Security Enhancements

The update also tightens security around Gitea Actions approval mechanisms. CVE-2026-104632 allowed a canceled workflow from a fork, which was awaiting approval, to execute on self-hosted runners if rerun. Another issue, CVE-2026-94205, only checked the event actor, permitting a maintainer-triggered event to run an untrusted contributor’s workflow without the necessary approval. Both these approval gaps have now been rectified.

Additional fixes encompass various other security flaws, including stored cross-site scripting (XSS) in container blobs, vulnerabilities related to duplicate Git tree entries that could conceal malicious files from code reviewers, and an installer flaw that could issue an existing administrator’s session without proper password verification. Permission-related patches also address lingering repository-transfer access issues and prevent deploy keys from inheriting repository-owner privileges.

What You Should Do

  • Upgrade Immediately: All Gitea administrators should prioritize upgrading their installations to version 28.1.0 without delay.
  • Backup Data: Before initiating the upgrade process, ensure a complete and verified backup of all Gitea data.
  • Review Release Notes: Carefully consult Gitea’s release notes for crucial information regarding breaking changes, new network rules (especially for egress control), the updated Git 2.25 minimum requirement, and altered workflow behavior.
  • Configure Egress Rules: If your environment requires strict outbound connection control, implement the new EGRESS_MODE = strict setting and explicitly whitelist allowed hosts as detailed in the release notes.
  • Monitor for Anomalies: Post-upgrade, closely monitor Gitea logs and network activity for any unusual behavior or connection attempts.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Microsoft Teams Phishing Scam Steals Credentials with Fake Login Page

Next Post

AI-Powered Attacks Breach South Korean Financial Firms, Steal Data

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
wolfSSH 1.6.0 Patches Critical MITM Host Key Verification Bypass Vulnerability
October 8, 2026
Malfex npm Malware Hides Executables in PNG Files to Infect Windows Devs
October 8, 2026
Critical Cisco Nexus Flaws Allow Root-Level Remote Code Execution
October 8, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us