CVE-2026-79960 Details
Description
When a push was authenticated with a deploy key, Gitea recorded the repository owner as the pusher, so permission checks in the push hook pipeline evaluated the owner instead of the deploy key. A holder of a writable deploy key could create protected tags without being on the tag allow list and change repository visibility through push options, for example making a private repository public. Pull requests created through the AGit flow with a deploy key were also attributed to the owner.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://blog.gitea.com/release-of-28.0.0/ | Gitea Limited | |
| https://github.com/go-gitea/gitea/pull/37306 | Gitea Limited | |
| https://github.com/go-gitea/gitea/releases/tag/v28.0.0 | Gitea Limited | |
| https://github.com/go-gitea/gitea/security/advisories/GHSA-7769-9pr9-m24h | Gitea Limited |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | Gitea Limited |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Oct 7, 2026 | CVE Modified | CISA-ADP |
| Oct 6, 2026 | New CVE Received | Gitea Limited |