CVE-2026-89182 - Gitea push-to-create bypass of FORCE_PRIVATE policy
CVE ID :CVE-2026-89182
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 28 minutes ago
Description :With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The default configuration is not affected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 28 minutes ago
Description :With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The default configuration is not affected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...