Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitea
Gitea gitea |
|
| Vendors & Products |
Gitea
Gitea gitea |
Tue, 06 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Gitea API endpoint for creating push mirrors (`POST /api/v1/repos/{owner}/{repo}/push_mirrors`) checked only whether mirroring was enabled and not the `[mirror] DISABLE_NEW_PUSH` setting that the web interface enforces. A repository administrator could therefore create new push mirrors on instances where the site administrator had disabled them. A push mirror pushes all refs of the repository to a remote chosen by the caller, on each commit or on a schedule. | |
| Title | Gitea push mirror API bypass of DISABLE_NEW_PUSH policy | |
| Weaknesses | CWE-863 | |
| References |
|
Status: PUBLISHED
Assigner: Gitea
Published:
Updated: 2026-10-06T21:17:46.887Z
Reserved: 2026-10-04T21:59:53.577Z
Link: CVE-2026-97208
No data.
Status : Received
Published: 2026-10-06T22:17:07.927
Modified: 2026-10-06T22:17:07.927
Link: CVE-2026-97208
No data.
OpenCVE Enrichment
Updated: 2026-10-07T04:30:11Z