MinorCritical vulnerability
CVE-2026-79960 (CVSS 7.1)
NVD · officialPublished Oct 6, 2026Risk 23/100EPSS 0.1%
When a push was authenticated with a deploy key, Gitea recorded the repository owner as the pusher, so permission checks in the push hook pipeline evaluated the owner instead of the deploy key. A holder of a writable deploy key could create protected tags without being on the tag allow list and change repository visibility through push options, for example making a private repository public. Pull requests created through the AGit flow with a deploy key were also attributed to the owner.
Technical details
CVSS
7.1
AV:NetworkAC:LowPR:LowUI:NoneC:HighI:LowA:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source