Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Gitea Addresses Critical Security Flaws with New Update

Gitea Addresses Critical Security Flaws with New Update

Posted on October 8, 2026 By CWS

Gitea has announced the release of a crucial security update addressing 27 vulnerabilities found in versions 28.0.0 and 28.1.0. Among these, significant concerns include a critical SSH authentication bypass and server-side request forgery (SSRF) issues. This update is considered a top priority for administrators managing development infrastructure.

Comprehensive Patch Details

The latest patches cover a wide range of security aspects, such as account access, repository permissions, and automated workflows. The update, released on September 30, 2023, encompasses 20 Common Vulnerabilities and Exposures (CVEs) in its notes. Although initially listed under version 28.0.0, the total 27 vulnerabilities include those addressed in the subsequent 28.1.0 update. Notably, Gitea has dropped its historical version prefix, designating this release as 28.0.0 instead of 1.28.0.

Critical Vulnerability Insights

A particularly severe issue, identified as CVE-2026-103059, holds a Common Vulnerability Scoring System (CVSS) score of 9.1. This flaw affects deployments using Gitea’s internal SSH server, where public-key lookups used an SQL LIKE comparison that ignored case sensitivity on certain databases, including SQLite. This vulnerability could potentially allow an attacker to authenticate as another user if they craft a specific RSA key that matches a registered key’s case variant.

To mitigate this risk, Gitea now verifies keys through their fingerprints, eliminating the unsafe text comparison method. This change ensures a more secure authentication process by preventing unauthorized access through crafted keys.

Enhancements and Configuration Changes

Additional vulnerabilities have been rectified, such as repository migration flaws that allowed bypassing of outbound connection rules. For example, CVE-2026-70357 exploited a timing gap in hostname validation, which could redirect connections to unintended internal hosts. Updates now route Git operations through an internal proxy, enforcing strict outbound access rules.

Administrators are advised to review and adjust configuration settings before upgrading, with recommendations to apply a deny-by-default policy by setting EGRESS_MODE to strict. This requires explicitly listing allowed hosts, thereby enhancing security.

Moreover, updates address Gitea Actions approval processes. Specific vulnerabilities that allowed unauthorized workflow execution have been rectified, ensuring all actions undergo necessary approval checks.

In conclusion, administrators should prioritize upgrading to version 28.1.0 to secure their systems. Gitea’s release notes provide comprehensive guidance on new network rules and workflow behavior changes. The update not only resolves current vulnerabilities but also fortifies the platform against potential future threats.

Cyber Security News Tags:Administrator, CVE vulnerabilities, Cybersecurity, data protection, Gitea, Gitea Actions, Infrastructure, network security, repository permissions, security update, software flaws, software update, SQL vulnerability, SSH authentication, SSRF

Post navigation

Previous Post: US Offers $10 Million for Information on Chinese Hacker
Next Post: SonicWall, Splunk Address Severe Security Flaws

Related Posts

Microsoft 365 Search Issue Affects Global Users Microsoft 365 Search Issue Affects Global Users Cyber Security News
PoC Exploits for CitrixBleed2 Flaw Released – Attackers Can Exfiltrate 127 Bytes Per Request PoC Exploits for CitrixBleed2 Flaw Released – Attackers Can Exfiltrate 127 Bytes Per Request Cyber Security News
How AI Is Redefining Threat Detection In The Cloud Era How AI Is Redefining Threat Detection In The Cloud Era Cyber Security News
Hackers Exploit Fake CAPTCHA to Disable Security Hackers Exploit Fake CAPTCHA to Disable Security Cyber Security News
U.S. Agencies Alert on Siemens PLC Cyber Threats U.S. Agencies Alert on Siemens PLC Cyber Threats Cyber Security News
OpenAI Faces Lawsuit Over ChatGPT Data Sharing Practices OpenAI Faces Lawsuit Over ChatGPT Data Sharing Practices Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • wolfSSH 1.6.0 Addresses Critical Security Vulnerabilities
  • SonicWall, Splunk Address Severe Security Flaws
  • Gitea Addresses Critical Security Flaws with New Update
  • US Offers $10 Million for Information on Chinese Hacker
  • AI-Powered Breach Hits South Korean Financial Sector

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • wolfSSH 1.6.0 Addresses Critical Security Vulnerabilities
  • SonicWall, Splunk Address Severe Security Flaws
  • Gitea Addresses Critical Security Flaws with New Update
  • US Offers $10 Million for Information on Chinese Hacker
  • AI-Powered Breach Hits South Korean Financial Sector

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark