GITEA has released a major security update covering 28.0.0 and 28.1.0 that addresses 27 CVEs, spanning fixes for server-side request forgery, an installer authentication bypass, and multiple Gitea Actions approval bypasses. The disclosure notes an overall run of fixes across older versions (notably 1.27.3 and earlier) and newer releases, with the recommendation to upgrade to 28.1.0.
The highest severity cited is 9.1 (CVSSv3) for CVE-2026-103059, an built-in SSH server authentication bypass tied to case-folding of keys, though the advisories indicate that exploitation is not confirmed in the wild at this time. Overall, the package lists 1 Critical, 3 High, 3 Medium, and 20 Unrated vulnerabilities, with no confirmed active exploitation reported.
Key flaws described include CVE-2026-96404 (an installer authentication bypass for existing accounts) and CVE-2026-101027 (migration SSRF due to address checks on the allowed domains list), which together enable potential account takeover and internal access under certain conditions. Four issues affect Gitea Actions, enabling code from fork pull requests to reach runners without proper approval. The update also contains other fixes, including privacy fixes and an OAuth2-related improvement in 28.1.0.
Practically, administrators are urged to upgrade immediately to 28.1.0, keep the web installer locked, restrict migrations and mirrors, require approval for forked PR workflows, and review recent Actions runs while the rollout progresses.