Gitea has announced the release of a crucial security update addressing 27 vulnerabilities found in versions 28.0.0 and 28.1.0. Among these, significant concerns include a critical SSH authentication bypass and server-side request forgery (SSRF) issues. This update is considered a top priority for administrators managing development infrastructure.
Comprehensive Patch Details
The latest patches cover a wide range of security aspects, such as account access, repository permissions, and automated workflows. The update, released on September 30, 2023, encompasses 20 Common Vulnerabilities and Exposures (CVEs) in its notes. Although initially listed under version 28.0.0, the total 27 vulnerabilities include those addressed in the subsequent 28.1.0 update. Notably, Gitea has dropped its historical version prefix, designating this release as 28.0.0 instead of 1.28.0.
Critical Vulnerability Insights
A particularly severe issue, identified as CVE-2026-103059, holds a Common Vulnerability Scoring System (CVSS) score of 9.1. This flaw affects deployments using Gitea’s internal SSH server, where public-key lookups used an SQL LIKE comparison that ignored case sensitivity on certain databases, including SQLite. This vulnerability could potentially allow an attacker to authenticate as another user if they craft a specific RSA key that matches a registered key’s case variant.
To mitigate this risk, Gitea now verifies keys through their fingerprints, eliminating the unsafe text comparison method. This change ensures a more secure authentication process by preventing unauthorized access through crafted keys.
Enhancements and Configuration Changes
Additional vulnerabilities have been rectified, such as repository migration flaws that allowed bypassing of outbound connection rules. For example, CVE-2026-70357 exploited a timing gap in hostname validation, which could redirect connections to unintended internal hosts. Updates now route Git operations through an internal proxy, enforcing strict outbound access rules.
Administrators are advised to review and adjust configuration settings before upgrading, with recommendations to apply a deny-by-default policy by setting EGRESS_MODE to strict. This requires explicitly listing allowed hosts, thereby enhancing security.
Moreover, updates address Gitea Actions approval processes. Specific vulnerabilities that allowed unauthorized workflow execution have been rectified, ensuring all actions undergo necessary approval checks.
In conclusion, administrators should prioritize upgrading to version 28.1.0 to secure their systems. Gitea’s release notes provide comprehensive guidance on new network rules and workflow behavior changes. The update not only resolves current vulnerabilities but also fortifies the platform against potential future threats.
