Gitea API Push Mirror Configuration Flaw Exposes Weakness
CVE-2026-97208
Currently unrated
What is CVE-2026-97208?
The Gitea API endpoint for creating push mirrors (POST /api/v1/repos/{owner}/{repo}/push_mirrors) has a critical oversight where it only verifies if mirroring is enabled, failing to check the [mirror] DISABLE_NEW_PUSH setting enforced by the web interface. This oversight allows repository administrators to create new push mirrors even when site administrators have disabled them. Such mirrors facilitate the transferring of all repository references to a remote location whenever a commit occurs or on a defined schedule, posing significant risks to repository integrity and security.
Affected Version(s)
Gitea 0 <= 28.0.0
