CVE-2026-97208

medium

Description

The Gitea API endpoint for creating push mirrors (`POST /api/v1/repos/{owner}/{repo}/push_mirrors`) checked only whether mirroring was enabled and not the `[mirror] DISABLE_NEW_PUSH` setting that the web interface enforces. A repository administrator could therefore create new push mirrors on instances where the site administrator had disabled them. A push mirror pushes all refs of the repository to a remote chosen by the caller, on each commit or on a schedule.

References

https://github.com/go-gitea/gitea/security/advisories/GHSA-8hhh-mqpg-jpxc

https://github.com/go-gitea/gitea/releases/tag/v28.1.0

https://github.com/go-gitea/gitea/pull/39507

https://github.com/go-gitea/gitea/pull/39501

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-94053

https://blog.gitea.com/release-of-28.1.0/

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-07

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 4.9

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Severity: Medium

EPSS

EPSS: 0.00161