Junglewise Threat Intelligence

CVE-2026-27775: Gitea incorrect authorization via cached branch permissions in pre-receive hook

CVE-2026-27775 · Severity: high · CVSS 8.8 · Published 2026-07-03

Technologies: code.gitea.io/gitea (Go), Gitea. Vendors: Go, Gitea.

Executive brief

A security flaw in Gitea, a popular self-hosted Git service, allows an attacker to gain full write access to a repository they should only have limited access to. If a user grants a maintainer permission to edit a specific branch in a pull request, the maintainer can exploit a caching error to bypass security checks and overwrite any other branch, including the main production code. This could lead to unauthorized code changes, data loss, or the introduction of malicious software into a project.

Technical details

An authorization bypass exists in Gitea's `HookPreReceive` handler due to a check-vs-use divergence. The `CanWriteCode()` function evaluates the `CanMaintainerWriteToBranch` permission but caches the result in the `preReceiveContext` for the duration of a `git push` session. When an attacker performs a multi-ref push, Gitea validates the first ref (e.g., a branch where the attacker has maintainer-edit rights) and caches a 'true' result. Subsequent refs in the same batch, such as the 'main' branch or protected tags, then reuse this cached 'true' value without re-evaluating permissions against the new branch name. This is further enabled by AGit-flow support which may downgrade initial access requirements from Write to Read, deferring full authorization to the flawed pre-receive hook.

Affected products

  • Gitea Gitea < 1.26.3

Timeline

  • 2026-06-21: advisory: Original GitHub Advisory published
  • 2026-07-21: disclosed

References

Related threats