With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The default configuration is not affected.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 06 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The default configuration is not affected.
Title Gitea push-to-create bypass of FORCE_PRIVATE policy
Weaknesses CWE-863
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Gitea

Published:

Updated: 2026-10-06T21:36:01.187Z

Reserved: 2026-10-04T22:02:04.881Z

Link: CVE-2026-89182

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T22:17:07.690

Modified: 2026-10-06T22:17:07.690

Link: CVE-2026-89182

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses