Repository Configuration Vulnerability in Gitea
CVE-2026-89182
Currently unrated
What is CVE-2026-89182?
Gitea has a vulnerability that arises when the FORCE_PRIVATE configuration is set to true. In this scenario, new repositories are intended to be created as private. However, a loophole allows the post-receive hook to set repo.private to false for empty repositories created via push. This permits any user with repository creation permission to inadvertently expose a repository as public, contravening the intended privacy policy of the Gitea instance. It is essential for users to review their instance configurations and apply the necessary patches to maintain compliance with privacy settings.
Affected Version(s)
Gitea 1.27.0 <= 28.0.0
