PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-95106 Gitea CVE debrief

A Gitea vulnerability allows a contributor to open a pull request with benign content displayed in diff and file views, while CI and checkouts use different, potentially attacker-controlled content. This issue is resolved in Gitea version 28.0.0. The vulnerability arises from Gitea accepting pushed Git trees with duplicate entries, which Git's consistency checks reject. Gitea's web views resolve such paths to the first entry, while `git checkout`, Gitea Actions, and release archives use the last. Defenders managing Gitea deployments should assess exposure and prioritize verification and remediation.

Vendor
Gitea
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-06
Original CVE updated
2026-10-07
Advisory published
2026-10-06
Advisory updated
2026-10-07

Who should care

Defenders managing Gitea deployments, especially those with untrusted contributors, should assess exposure and prioritize verification and remediation. This includes reviewing Gitea version information, monitoring for suspicious activity, and restricting contributor permissions to prevent unauthorized changes.

Why it matters

CVE-2026-95106 allows a contributor to bypass Gitea's content validation, potentially leading to malicious content execution in CI and checkouts. Defenders should verify Gitea deployments and prioritize remediation.

  • Verify Gitea version and apply patches to prevent potential malicious content execution.
  • Monitor for suspicious pull requests and CI pipeline activity.
  • Restrict contributor permissions to prevent unauthorized changes.

Technical summary

Gitea accepted pushed Git trees containing two entries with the same name, which Git's own consistency checks reject. Gitea's web views resolved such a path to the first entry, while `git checkout`, Gitea Actions, and release archives use the last. A contributor could open a pull request whose diff and file views show benign content while CI and checkouts at the same commit use different, attacker-controlled content.

Defensive priority

Defenders should prioritize verifying Gitea deployments, especially those with untrusted contributors, and upgrading to version 28.0.0 or applying patches.

Recommended defensive actions

  • Verify Gitea deployments for version 1.27.3 or earlier and upgrade to version 28.0.0 or apply patches.
  • Monitor pull requests and CI pipelines for potential malicious activity.
  • Restrict contributor permissions to prevent unauthorized changes.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and Gitea advisory provide details on the vulnerability. However, the exact scope of affected versions and potential impact require further verification. Affected versions are likely prior to 28.0.0. Defenders should verify Gitea deployments, especially those with untrusted contributors, and review the vendor advisory for specific version information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-95106 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-95106

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-95106 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-95106

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Gitea review and execution mismatch through duplicate tree entries

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/95xxx/CVE-2026-95106.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/security/advisories/GHSA-6pv5-8rp7-8c75

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/pull/39472

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://blog.gitea.com/release-of-28.0.0/

    Supplemental source - release-notes

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/releases/tag/v28.0.0

    Supplemental source - release-notes

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.