PatchSiren cyber security CVE debrief
CVE-2026-95106 Gitea CVE debrief
A Gitea vulnerability allows a contributor to open a pull request with benign content displayed in diff and file views, while CI and checkouts use different, potentially attacker-controlled content. This issue is resolved in Gitea version 28.0.0. The vulnerability arises from Gitea accepting pushed Git trees with duplicate entries, which Git's consistency checks reject. Gitea's web views resolve such paths to the first entry, while `git checkout`, Gitea Actions, and release archives use the last. Defenders managing Gitea deployments should assess exposure and prioritize verification and remediation.
- Vendor
- Gitea
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-06
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-06
- Advisory updated
- 2026-10-07
Who should care
Defenders managing Gitea deployments, especially those with untrusted contributors, should assess exposure and prioritize verification and remediation. This includes reviewing Gitea version information, monitoring for suspicious activity, and restricting contributor permissions to prevent unauthorized changes.
Why it matters
CVE-2026-95106 allows a contributor to bypass Gitea's content validation, potentially leading to malicious content execution in CI and checkouts. Defenders should verify Gitea deployments and prioritize remediation.
- Verify Gitea version and apply patches to prevent potential malicious content execution.
- Monitor for suspicious pull requests and CI pipeline activity.
- Restrict contributor permissions to prevent unauthorized changes.
Technical summary
Gitea accepted pushed Git trees containing two entries with the same name, which Git's own consistency checks reject. Gitea's web views resolved such a path to the first entry, while `git checkout`, Gitea Actions, and release archives use the last. A contributor could open a pull request whose diff and file views show benign content while CI and checkouts at the same commit use different, attacker-controlled content.
Defensive priority
Defenders should prioritize verifying Gitea deployments, especially those with untrusted contributors, and upgrading to version 28.0.0 or applying patches.
Recommended defensive actions
- Verify Gitea deployments for version 1.27.3 or earlier and upgrade to version 28.0.0 or apply patches.
- Monitor pull requests and CI pipelines for potential malicious activity.
- Restrict contributor permissions to prevent unauthorized changes.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and Gitea advisory provide details on the vulnerability. However, the exact scope of affected versions and potential impact require further verification. Affected versions are likely prior to 28.0.0. Defenders should verify Gitea deployments, especially those with untrusted contributors, and review the vendor advisory for specific version information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-95106 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-95106
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-95106 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-95106
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Gitea review and execution mismatch through duplicate tree entries
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/95xxx/CVE-2026-95106.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/security/advisories/GHSA-6pv5-8rp7-8c75
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/pull/39472
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://blog.gitea.com/release-of-28.0.0/
Supplemental source - release-notes
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/releases/tag/v28.0.0
Supplemental source - release-notes
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.