Gitea API Push Mirror Configuration Flaw Exposes Weakness
CVE-2026-97208

Currently unrated

Key Information:

Vendor

Gitea

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-97208?

The Gitea API endpoint for creating push mirrors (POST /api/v1/repos/{owner}/{repo}/push_mirrors) has a critical oversight where it only verifies if mirroring is enabled, failing to check the [mirror] DISABLE_NEW_PUSH setting enforced by the web interface. This oversight allows repository administrators to create new push mirrors even when site administrators have disabled them. Such mirrors facilitate the transferring of all repository references to a remote location whenever a commit occurs or on a defined schedule, posing significant risks to repository integrity and security.

Affected Version(s)

Gitea 0 <= 28.0.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

https://github.com/tao0845
https://github.com/silverwind
https://github.com/bircni
.