CVE-2026-89182

Source
https://cve.org/CVERecord?id=CVE-2026-89182
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89182.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89182
Aliases
  • GHSA-fx95-gwfc-grgc
Published
2026-10-06T21:36:01Z
Modified
2026-10-07T10:46:59Z
Summary
Gitea push-to-create bypass of FORCE_PRIVATE policy
Details

With [repository] FORCE_PRIVATE = true, Gitea creates new repositories as private, but the post-receive hook still applied the repo.private=false push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The default configuration is not affected.

Database specific
{
    "cna_assigner": "Gitea",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89182.json"
}
References

Affected packages

Git / github.com/go-gitea/gitea

Affected ranges

Type
GIT
Repo
https://github.com/go-gitea/gitea
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.27.0"
        },
        {
            "last_affected": "28.0.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.27.0-dev
v1.28.0-dev
v28.*
v28.0.0
v29.*
v29.0.0-dev

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89182.json"