PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97208 Gitea CVE debrief

The Gitea API endpoint for creating push mirrors did not properly enforce the DISABLE_NEW_PUSH policy, allowing repository administrators to create new push mirrors even when site administrators had disabled them. This could lead to unintended pushing of repository refs to a remote location. The issue arises from the API's failure to check the DISABLE_NEW_PUSH setting, which is enforced through the web interface. This discrepancy could be exploited by repository administrators to bypass the intended restrictions.

Vendor
Gitea
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-06
Original CVE updated
2026-10-07
Advisory published
2026-10-06
Advisory updated
2026-10-07

Who should care

Gitea instance administrators, repository administrators, and security teams responsible for monitoring and enforcing security policies on Gitea instances should be aware of this vulnerability. They need to verify their Gitea instance configurations to ensure that the DISABLE_NEW_PUSH policy is properly enforced and review repository administrator roles and permissions. Additionally, they should monitor Gitea instances for suspicious push mirror activity.

Why it matters

The CVE-2026-97208 vulnerability in Gitea's push mirror API could allow repository administrators to bypass the DISABLE_NEW_PUSH policy set by site administrators, potentially leading to unintended repository ref pushing.

  • Repository administrators could create new push mirrors despite site administrators disabling them
  • Potential for unintended pushing of repository refs to remote locations
  • Need for verification of Gitea instance configurations and repository administrator roles

Technical summary

The Gitea API endpoint for creating push mirrors did not check the DISABLE_NEW_PUSH setting, allowing repository administrators to create new push mirrors even when site administrators had disabled them. This vulnerability arises from the API's inadequate validation of the DISABLE_NEW_PUSH policy, which is a critical security control. The technical issue lies in the API's failure to enforce this policy, potentially leading to unauthorized pushing of repository refs to remote locations. Affected Gitea instances should be updated to enforce this policy properly.

Defensive priority

Repository administrators and site administrators should verify their Gitea instance configurations to ensure that the DISABLE_NEW_PUSH policy is properly enforced.

Recommended defensive actions

  • Verify Gitea instance configurations to ensure DISABLE_NEW_PUSH policy is enforced
  • Review repository administrator roles and permissions
  • Monitor Gitea instance for suspicious push mirror activity
  • Perform a thorough review of existing push mirrors to identify potential unauthorized configurations
  • Implement additional logging and monitoring for push mirror activities
  • Conduct regular security audits of Gitea instance configurations
  • Ensure that repository administrators are aware of the DISABLE_NEW_PUSH policy and its implications

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description and affected versions. The Gitea API's push mirror creation endpoint did not validate the DISABLE_NEW_PUSH policy, which is a critical security setting. This oversight allows repository administrators to create push mirrors even when the site administrator has disabled this feature. Evidence from the CVE record and source item confirms this vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97208 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97208

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97208 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97208

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Gitea push mirror API bypass of DISABLE_NEW_PUSH policy

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/97xxx/CVE-2026-97208.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/security/advisories/GHSA-8hhh-mqpg-jpxc

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/pull/39501

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/pull/39507

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://blog.gitea.com/release-of-28.1.0/

    Supplemental source - release-notes

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/releases/tag/v28.1.0

    Supplemental source - release-notes

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.