Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-89430

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Oct 06, 2026
Vendor unknown

Description

Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created. Each synchronization passed the stored address directly to `git push`, so a name that later resolved to a blocked or internal address was still reached. A user with administrator access to a repository, which includes repositories they create themselves, could aim push mirror synchronization at internal Git services and force-push the repository's contents to them.

References