# Gitea 28.x Patches 27 Security Flaws Including Critical SSH Public-Key Authentication Bypass (CVE-2026-103059), SSRF/DNS Rebinding and Actions Approval Bypasses

> Gitea 28.0.0 and 28.1.0 fix 27 security flaws, headlined by CVE-2026-103059 (CVSS 9.1), a case-insensitive SSH public-key lookup that lets a crafted RSA key match another user's registered key on the built-in SSH server. Other fixes cover SSRF via DNS rebinding and egress allowlist bypasses, and Gitea Actions fork-PR approval bypasses that can reach self-hosted runners. No active exploitation of these flaws is reported.

- **Published:** 2026-10-08T00:00:00Z
- **Last reviewed:** 2026-10-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3046
- **ID:** TL-2026-3046
- **Severity:** CRITICAL (CVSS 9.1)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 4 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-103059, CVE-2026-70357, CVE-2026-101027, CVE-2026-101029, CVE-2026-89430, CVE-2026-104632, CVE-2026-94205, CVE-2026-104626, CVE-2026-103667, CVE-2026-95106, CVE-2026-103670, CVE-2026-96399, CVE-2026-96404, CVE-2026-96589, CVE-2026-96400, CVE-2026-104636, CVE-2026-79960, CVE-2026-103504, CVE-2026-96580, CVE-2026-95112

## Description

Gitea (a self-hosted Git service) shipped 28.0.0 on 2026-09-30 (the project dropped the '1.' version prefix) with security notes listing 20 CVEs, followed by 28.1.0 (2026-10-06), bringing the reported total to 27 fixed flaws. Gitea advises upgrading as soon as possible.

CVE-2026-103059 (CVSS 9.1, critical) affects deployments using Gitea's built-in SSH server. The public-key lookup compared key text with an SQL LIKE comparison that is case-insensitive on some databases, including the default SQLite. A specially crafted RSA key could therefore match a different user's registered key. Per the reporting, exploitation requires a suitable case variant of the victim's public key together with its matching private key, so it is not a general bypass. The fix (PR #39423, reported by @carlini) identifies presented keys by fingerprint instead of text comparison.

A cluster of SSRF/egress flaws was fixed by routing migration, mirror and Git network operations through an internal proxy that applies outbound rules (PR #39426): CVE-2026-70357 (DNS rebinding between hostname validation and the Git connection during migrations/mirrors), CVE-2026-101027 (allowed-domain hostnames skipped the destination IP check), CVE-2026-101029 (multi-answer DNS bypassed the egress allow-list), CVE-2026-89430 (push mirrors could later reach internal Git hosts and force-push to them), CVE-2026-96400 (non-empty migrations ALLOWED_DOMAINS permitted reserved and link-local addresses; default config not affected) and CVE-2026-104636 (Git HTTP redirects bypassed the outbound host policy).

Gitea Actions approval logic had several bypasses (PR #39399): CVE-2026-104632 (re-running an approval-pending, cancelled fork PR run could execute on self-hosted runners without approval), CVE-2026-104626 (GHSA-93pj-3x56-5gc2, CVSS 9.0: approving a fork PR run revived already-cancelled jobs; advisory notes it needs Actions enabled, a matching runner and a later legitimate maintainer approval; affects versions up to and including 1.27.3), CVE-2026-94205 (approval check ignored the PR author, so a maintainer-triggered event could run untrusted fork workflows), CVE-2026-103670 (an unapproved fork PR run could cancel trusted runs in the same concurrency group) and CVE-2026-96580 (large static strategy.matrix in unapproved fork PR workflows could exhaust memory).

Other fixes: CVE-2026-103667 (container registry served attacker-controlled content types, stored XSS), CVE-2026-95106 (duplicate Git tree entry names could make Gitea show a different file than checkout/CI uses, hiding malicious files from reviewers), CVE-2026-96404 (re-running the installer issued an admin session without verifying the password), CVE-2026-96589 (rejected/cancelled repository transfers left the recipient's temporary access), CVE-2026-79960 (deploy-key pushes ran hooks as the repo owner, bypassing protected-tag and push-option checks), CVE-2026-103504 (lowering a team's permission via the API left prior per-unit permissions), CVE-2026-96399 (crash via crafted external issue tracker pattern) and CVE-2026-95112 (quadratic issue-reference parsing).

Upgrade notes: strict egress mode (EGRESS_MODE = strict) gives deny-by-default outbound rules; Git 2.25.0+ is required; self-registration is disabled unless DISABLE_REGISTRATION = false; completed Actions runs are deleted after 400 days by default; WebSocket notifications replace SSE. Sources do not state CVSS for most CVEs or per-CVE affected ranges. The sources mention no public PoC and no exploitation of these flaws; separate Gitea exploitation reporting (CVE-2026-60004 diffpatch RCE, fixed in 1.27.1) is a different vulnerability.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1059.007 JavaScript
- T1098 Account Manipulation
- T1548 Abuse Elevation Control Mechanism
- T1021.004 SSH
- T1213.003 Code Repositories
- T1565.001 Stored Data Manipulation
- T1499.003 Application Exhaustion Flood
- T1499.004 Application or System Exploitation

## Sources

- [Gitea Patches 27 Security Flaws, Including Critical SSH Authentication Bypass and SSRF](https://cybersecuritynews.com/gitea-patches-27-security-flaws/)
- [Gitea 28.0.0 release notes (20 CVEs, upgrade notes)](https://blog.gitea.com/release-of-28.0.0/)
- [Gitea v28.1.0 release (GitHub)](https://github.com/go-gitea/gitea/releases/tag/v28.1.0)
- [go-gitea/gitea security advisories](https://github.com/go-gitea/gitea/security/advisories)
- [GHSA-93pj-3x56-5gc2: Cancelled fork-PR Actions jobs revived by later approval (CVE-2026-104626)](https://github.com/go-gitea/gitea/security/advisories/GHSA-93pj-3x56-5gc2)
- [Hackers exploiting Gitea N-day RCE vulnerability (CVE-2026-60004, separate flaw; context only)](https://cybersecuritynews.com/hackers-exploiting-gitea-n-day-rce-vulnerability/)
- [CVE-2026-58423 Gitea SSH LFS authentication bypass (prior unrelated Gitea SSH flaw; context only)](https://cveawg.mitre.org/api/cve/CVE-2026-58423)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3046
