Executive brief
Gitea is a self-hosted software development platform similar to GitHub. A security flaw allows users who have previously forked a public project to continue receiving new updates and private code even after the original project has been made private. This could lead to the unauthorized exposure of sensitive intellectual property or internal code to individuals who should no longer have access.
Technical details
An improper access control vulnerability exists in Gitea's `POST /api/v1/repos/{owner}/{repo}/merge-upstream` endpoint. When a parent repository is transitioned from public to private, Gitea does not verify the fork owner's current permissions on the parent repository during synchronization requests. This allows an attacker with an existing fork to pull new commits and sensitive content added to the parent repository after it was made private. The vulnerability is reachable over the network without specific new privileges beyond owning a pre-existing fork. The issue is resolved in Gitea version 1.26.3.
Affected products
- Gitea Gitea < 1.26.3
Timeline
- 2026-06-21: disclosed
- 2026-07-03: advisory: NVD publication date
- 2026-07-21: patched: GitHub Advisory reviewed and published