PatchSiren cyber security CVE debrief
CVE-2026-97208 Gitea CVE debrief
The Gitea API endpoint for creating push mirrors did not properly enforce the DISABLE_NEW_PUSH policy, allowing repository administrators to create new push mirrors even when site administrators had disabled them. This could lead to unintended pushing of repository refs to a remote location. The issue arises from the API's failure to check the DISABLE_NEW_PUSH setting, which is enforced through the web interface. This discrepancy could be exploited by repository administrators to bypass the intended restrictions.
- Vendor
- Gitea
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-06
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-06
- Advisory updated
- 2026-10-07
Who should care
Gitea instance administrators, repository administrators, and security teams responsible for monitoring and enforcing security policies on Gitea instances should be aware of this vulnerability. They need to verify their Gitea instance configurations to ensure that the DISABLE_NEW_PUSH policy is properly enforced and review repository administrator roles and permissions. Additionally, they should monitor Gitea instances for suspicious push mirror activity.
Why it matters
The CVE-2026-97208 vulnerability in Gitea's push mirror API could allow repository administrators to bypass the DISABLE_NEW_PUSH policy set by site administrators, potentially leading to unintended repository ref pushing.
- Repository administrators could create new push mirrors despite site administrators disabling them
- Potential for unintended pushing of repository refs to remote locations
- Need for verification of Gitea instance configurations and repository administrator roles
Technical summary
The Gitea API endpoint for creating push mirrors did not check the DISABLE_NEW_PUSH setting, allowing repository administrators to create new push mirrors even when site administrators had disabled them. This vulnerability arises from the API's inadequate validation of the DISABLE_NEW_PUSH policy, which is a critical security control. The technical issue lies in the API's failure to enforce this policy, potentially leading to unauthorized pushing of repository refs to remote locations. Affected Gitea instances should be updated to enforce this policy properly.
Defensive priority
Repository administrators and site administrators should verify their Gitea instance configurations to ensure that the DISABLE_NEW_PUSH policy is properly enforced.
Recommended defensive actions
- Verify Gitea instance configurations to ensure DISABLE_NEW_PUSH policy is enforced
- Review repository administrator roles and permissions
- Monitor Gitea instance for suspicious push mirror activity
- Perform a thorough review of existing push mirrors to identify potential unauthorized configurations
- Implement additional logging and monitoring for push mirror activities
- Conduct regular security audits of Gitea instance configurations
- Ensure that repository administrators are aware of the DISABLE_NEW_PUSH policy and its implications
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description and affected versions. The Gitea API's push mirror creation endpoint did not validate the DISABLE_NEW_PUSH policy, which is a critical security setting. This oversight allows repository administrators to create push mirrors even when the site administrator has disabled this feature. Evidence from the CVE record and source item confirms this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-97208 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-97208
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-97208 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97208
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Gitea push mirror API bypass of DISABLE_NEW_PUSH policy
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/97xxx/CVE-2026-97208.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/security/advisories/GHSA-8hhh-mqpg-jpxc
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/pull/39501
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/pull/39507
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://blog.gitea.com/release-of-28.1.0/
Supplemental source - release-notes
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/releases/tag/v28.1.0
Supplemental source - release-notes
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.