Threat reportVulnerabilityTL-2026-3046

Gitea 28.x Patches 27 Security Flaws Including Critical SSH Public-Key Authentication Bypass (CVE-2026-103059), SSRF/DNS Rebinding and Actions Approval Bypasses

criticalPATCHED

Gitea 28.x Patches 27 Security Flaws Including Critical SSH (TL-2026-3046) is a critical-severity software vulnerability scored CVSS 9.1, first published 2026-10-08. It has no confirmed attribution, affects Gitea Gitea (self-hosted Git service; Go module gitea.dev), references 20 CVEs (CVE-2026-103059, CVE-2026-70357, CVE-2026-101027), maps to 11 MITRE ATT&CK techniques (T1021.004, T1059, T1059.007), and is covered by 9 detection rules and 4 indicators of compromise.

CVSS
9.1/10Critical
CVEs
20Referenced vulnerabilities
Techniques
11MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
4Indicators of compromise

Key facts for TL-2026-3046

Threat ID
TL-2026-3046
Severity
CRITICAL
CVSS
9.1
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, software-development, critical-infrastructure, government administration
Target regions
Global
Detection rules
9
Indicators of compromise
4

How Gitea 28.x Patches 27 Security Flaws Including Critical SSH works

Gitea 28.0.0 and 28.1.0 fix 27 security flaws, headlined by CVE-2026-103059 (CVSS 9.1), a case-insensitive SSH public-key lookup that lets a crafted RSA key match another user's registered key on the built-in SSH server. Other fixes cover SSRF via DNS rebinding and egress allowlist bypasses, and Gitea Actions fork-PR approval bypasses that can reach self-hosted runners. No active exploitation of these flaws is reported.

Gitea (a self-hosted Git service) shipped 28.0.0 on 2026-09-30 (the project dropped the '1.' version prefix) with security notes listing 20 CVEs, followed by 28.1.0 (2026-10-06), bringing the reported total to 27 fixed flaws. Gitea advises upgrading as soon as possible.

CVE-2026-103059 (CVSS 9.1, critical) affects deployments using Gitea's built-in SSH server. The public-key lookup compared key text with an SQL LIKE comparison that is case-insensitive on some databases, including the default SQLite. A specially crafted RSA key could therefore match a different user's registered key. Per the reporting, exploitation requires a suitable case variant of the victim's public key together with its matching private key, so it is not a general bypass. The fix (PR #39423, reported by @carlini) identifies presented keys by fingerprint instead of text comparison.

A cluster of SSRF/egress flaws was fixed by routing migration, mirror and Git network operations through an internal proxy that applies outbound rules (PR #39426): CVE-2026-70357 (DNS rebinding between hostname validation and the Git connection during migrations/mirrors), CVE-2026-101027 (allowed-domain hostnames skipped the destination IP check), CVE-2026-101029 (multi-answer DNS bypassed the egress allow-list), CVE-2026-89430 (push mirrors could later reach internal Git hosts and force-push to them), CVE-2026-96400 (non-empty migrations ALLOWED_DOMAINS permitted reserved and link-local addresses; default config not affected) and CVE-2026-104636 (Git HTTP redirects bypassed the outbound host policy).

Gitea Actions approval logic had several bypasses (PR #39399): CVE-2026-104632 (re-running an approval-pending, cancelled fork PR run could execute on self-hosted runners without approval), CVE-2026-104626 (GHSA-93pj-3x56-5gc2, CVSS 9.0: approving a fork PR run revived already-cancelled jobs; advisory notes it needs Actions enabled, a matching runner and a later legitimate maintainer approval; affects versions up to and including 1.27.3), CVE-2026-94205 (approval check ignored the PR author, so a maintainer-triggered event could run untrusted fork workflows), CVE-2026-103670 (an unapproved fork PR run could cancel trusted runs in the same concurrency group) and CVE-2026-96580 (large static strategy.matrix in unapproved fork PR workflows could exhaust memory).

Other fixes: CVE-2026-103667 (container registry served attacker-controlled content types, stored XSS), CVE-2026-95106 (duplicate Git tree entry names could make Gitea show a different file than checkout/CI uses, hiding malicious files from reviewers), CVE-2026-96404 (re-running the installer issued an admin session without verifying the password), CVE-2026-96589 (rejected/cancelled repository transfers left the recipient's temporary access), CVE-2026-79960 (deploy-key pushes ran hooks as the repo owner, bypassing protected-tag and push-option checks), CVE-2026-103504 (lowering a team's permission via the API left prior per-unit permissions), CVE-2026-96399 (crash via crafted external issue tracker pattern) and CVE-2026-95112 (quadratic issue-reference parsing).

Upgrade notes: strict egress mode (EGRESS_MODE = strict) gives deny-by-default outbound rules; Git 2.25.0+ is required; self-registration is disabled unless DISABLE_REGISTRATION = false; completed Actions runs are deleted after 400 days by default; WebSocket notifications replace SSE. Sources do not state CVSS for most CVEs or per-CVE affected ranges. The sources mention no public PoC and no exploitation of these flaws; separate Gitea exploitation reporting (CVE-2026-60004 diffpatch RCE, fixed in 1.27.1) is a different vulnerability.

MITRE ATT&CK techniques used in TL-2026-3046

Lateral Movement

T1021.004 SSH

Execution

T1059 Command and Scripting Interpreter; T1059.007 JavaScript

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Persistence

T1098 Account Manipulation

Collection

T1213.003 Code Repositories

Impact

T1499.003 Application Exhaustion Flood; T1499.004 Application or System Exploitation; T1565.001 Stored Data Manipulation

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

Affected products and versions in Gitea 28.x Patches 27 Security Flaws Including Critical SSH

  • Gitea — Gitea (self-hosted Git service; Go module gitea.dev)
    Vulnerable versions: Versions prior to 28.0.0 (GHSA-93pj-3x56-5gc2 / CVE-2026-104626: up to and including 1.27.3); per-CVE ranges not stated in sources
    Fixed in: 28.0.0; 28.1.0

Remediation for Gitea 28.x Patches 27 Security Flaws Including Critical SSH

Patches

  • Gitea 28.0.0 (2026-09-30, 20 CVEs)
  • Gitea 28.1.0 (2026-10-06, completes the 27 fixes)

Immediate actions

  • Back up data, review breaking changes, then upgrade Gitea to 28.1.0
  • Where the built-in SSH server is used, upgrade first to fix CVE-2026-103059 (key lookup by fingerprint)
  • Require manual approval for fork PR workflows and review self-hosted runner exposure to fork workflows

Workarounds

  • Source notes Git 2.25.0 minimum is required by 28.x; set RUN_RETENTION_DAYS = 0 in [actions] before upgrading to retain completed runs
  • Set ROOT_URL (the [server] DOMAIN setting is ignored for registration/installer logic) and keep DISABLE_REGISTRATION enabled unless needed

Longer-term hardening

  • Set EGRESS_MODE = strict and explicitly list allowed hosts for migrations, mirrors and Git network operations
  • Isolate self-hosted Actions runners from internal networks and secrets
  • Disable open registration if not needed; review installer exposure and deploy-key scopes

CVEs associated with Gitea 28.x Patches 27 Security Flaws Including Critical SSH

  • CVE-2026-103059
  • CVE-2026-70357
  • CVE-2026-101027
  • CVE-2026-101029
  • CVE-2026-89430
  • CVE-2026-104632
  • CVE-2026-94205
  • CVE-2026-104626
  • CVE-2026-103667
  • CVE-2026-95106
  • CVE-2026-103670
  • CVE-2026-96399
  • CVE-2026-96404
  • CVE-2026-96589
  • CVE-2026-96400
  • CVE-2026-104636
  • CVE-2026-79960
  • CVE-2026-103504
  • CVE-2026-96580
  • CVE-2026-95112

Weaknesses (CWE) in Gitea 28.x Patches 27 Security Flaws Including Critical SSH

CWE-841

Timeline of Gitea 28.x Patches 27 Security Flaws Including Critical SSH

  • Context: separate Gitea diffpatch RCE (CVE-2026-60004, CVSS 9.8) fixed in 1.27.1; not one of the 27 flaws
  • Context: exploitation of the separate CVE-2026-60004 RCE by the Red Heron actor reported publicly, underscoring that internet-exposed Gitea servers are actively targeted
  • Gitea 28.0.0 released (version prefix '1.' dropped); security notes list 20 CVEs including CVE-2026-103059, the SSRF/DNS rebinding set and the Actions approval bypasses, with an ASAP upgrade recommendation
  • Batch of GitHub security advisories for go-gitea/gitea published, including GHSA-93pj-3x56-5gc2 (CVE-2026-104626, Critical) for cancelled fork-PR Actions jobs revived by later approval
  • Gitea 28.1.0 released; with it the reported total of fixed security flaws reaches 27
  • Cyber Security News reports the 27 fixes, headlined by CVE-2026-103059 (CVSS 9.1); no active exploitation of the newly fixed flaws is reported

Sources cited for Gitea 28.x Patches 27 Security Flaws Including Critical SSH

Detection coverage for TL-2026-3046

As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3046 across Splunk SPL, Microsoft KQL and Sigma, covering 4 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
4 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats