Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Gitea Addresses Critical Security Flaws with New Update

Gitea Addresses Critical Security Flaws with New Update

Posted on October 8, 2026 By CWS

Gitea has announced the release of a crucial security update addressing 27 vulnerabilities found in versions 28.0.0 and 28.1.0. Among these, significant concerns include a critical SSH authentication bypass and server-side request forgery (SSRF) issues. This update is considered a top priority for administrators managing development infrastructure.

Comprehensive Patch Details

The latest patches cover a wide range of security aspects, such as account access, repository permissions, and automated workflows. The update, released on September 30, 2023, encompasses 20 Common Vulnerabilities and Exposures (CVEs) in its notes. Although initially listed under version 28.0.0, the total 27 vulnerabilities include those addressed in the subsequent 28.1.0 update. Notably, Gitea has dropped its historical version prefix, designating this release as 28.0.0 instead of 1.28.0.

Critical Vulnerability Insights

A particularly severe issue, identified as CVE-2026-103059, holds a Common Vulnerability Scoring System (CVSS) score of 9.1. This flaw affects deployments using Gitea’s internal SSH server, where public-key lookups used an SQL LIKE comparison that ignored case sensitivity on certain databases, including SQLite. This vulnerability could potentially allow an attacker to authenticate as another user if they craft a specific RSA key that matches a registered key’s case variant.

To mitigate this risk, Gitea now verifies keys through their fingerprints, eliminating the unsafe text comparison method. This change ensures a more secure authentication process by preventing unauthorized access through crafted keys.

Enhancements and Configuration Changes

Additional vulnerabilities have been rectified, such as repository migration flaws that allowed bypassing of outbound connection rules. For example, CVE-2026-70357 exploited a timing gap in hostname validation, which could redirect connections to unintended internal hosts. Updates now route Git operations through an internal proxy, enforcing strict outbound access rules.

Administrators are advised to review and adjust configuration settings before upgrading, with recommendations to apply a deny-by-default policy by setting EGRESS_MODE to strict. This requires explicitly listing allowed hosts, thereby enhancing security.

Moreover, updates address Gitea Actions approval processes. Specific vulnerabilities that allowed unauthorized workflow execution have been rectified, ensuring all actions undergo necessary approval checks.

In conclusion, administrators should prioritize upgrading to version 28.1.0 to secure their systems. Gitea’s release notes provide comprehensive guidance on new network rules and workflow behavior changes. The update not only resolves current vulnerabilities but also fortifies the platform against potential future threats.

Cyber Security News Tags:Administrator, CVE vulnerabilities, Cybersecurity, data protection, Gitea, Gitea Actions, Infrastructure, network security, repository permissions, security update, software flaws, software update, SQL vulnerability, SSH authentication, SSRF

Post navigation

Previous Post: US Offers $10 Million for Information on Chinese Hacker

Related Posts

Python-Based Malware Targets Windows for Credential Theft Python-Based Malware Targets Windows for Credential Theft Cyber Security News
OpenAI Launches  ChatGPT Go Plan with Unlimited Access to GPT-5 OpenAI Launches $4 ChatGPT Go Plan with Unlimited Access to GPT-5 Cyber Security News
Hackers Actively Exploiting 7-Zip RCE Vulnerability in the Wild Hackers Actively Exploiting 7-Zip RCE Vulnerability in the Wild Cyber Security News
OpenClaw 2026.2.12 Update Enhances Security with 40+ Fixes OpenClaw 2026.2.12 Update Enhances Security with 40+ Fixes Cyber Security News
Critical Flaw in Trivy Scanner Added to CISA’s Vulnerability List Critical Flaw in Trivy Scanner Added to CISA’s Vulnerability List Cyber Security News
MCP Servers Found with Thousands of Security Flaws MCP Servers Found with Thousands of Security Flaws Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Gitea Addresses Critical Security Flaws with New Update
  • US Offers $10 Million for Information on Chinese Hacker
  • AI-Powered Breach Hits South Korean Financial Sector
  • Rein Security Secures $25M to Enhance AI Runtime Protection
  • Wazza Phishkit Poses Threat to Key Sectors Globally

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Gitea Addresses Critical Security Flaws with New Update
  • US Offers $10 Million for Information on Chinese Hacker
  • AI-Powered Breach Hits South Korean Financial Sector
  • Rein Security Secures $25M to Enhance AI Runtime Protection
  • Wazza Phishkit Poses Threat to Key Sectors Globally

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark