Repository Configuration Vulnerability in Gitea
CVE-2026-89182

Currently unrated

Key Information:

Vendor

Gitea

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-89182?

Gitea has a vulnerability that arises when the FORCE_PRIVATE configuration is set to true. In this scenario, new repositories are intended to be created as private. However, a loophole allows the post-receive hook to set repo.private to false for empty repositories created via push. This permits any user with repository creation permission to inadvertently expose a repository as public, contravening the intended privacy policy of the Gitea instance. It is essential for users to review their instance configurations and apply the necessary patches to maintain compliance with privacy settings.

Affected Version(s)

Gitea 1.27.0 <= 28.0.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

https://github.com/manus-pi
https://github.com/silverwind
https://github.com/bircni
.