Git Repository Migration Vulnerability in Gitea by Gitea
CVE-2026-57894

8.5HIGH

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-57894?

A vulnerability exists in Gitea that allows unauthorized internal Git repository exfiltration due to improper handling of HTTP redirects during repository migration processes. This flaw arises when the application follows Git HTTP redirects after allowing or blocking URLs, potentially exposing sensitive code and data to unauthorized users. Users of Gitea version 1.27.0 should apply available patches to mitigate this risk and ensure secure repository management.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

cyberlanc3r
.