External risk intelligence

Gitea Path Confusion Vulnerability Allows Content Discrepancy

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-95106

Gitea is a self-hosted Git service commonly deployed as an internet-facing web application to facilitate remote code collaboration, pull requests, and CI/CD integrations. Its primary purpose involves serving web content and API endpoints to external users, making it a commonly exposed service in many development environments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects Gitea, a self-hosted Git service. It allows for malicious code to be hidden within pull requests, appearing benign in review but executing differently during checks or checkouts. The primary concern is confirming if your Gitea instances are exposed and if this specific issue is relevant to your environment.

  • Hidden code in pull requests.
  • Discrepancy between review and execution.
  • Confirm Gitea exposure and relevance.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by pushing a Git tree containing duplicate file names to a repository. This could lead to a situation where the web interface displays one version of the content, while automated processes like CI/CD or code checkouts retrieve a different, malicious version controlled by the attacker.

  • Entry condition: Attacker pushes a crafted Git tree.
  • Trigger point: Content is viewed or checked out.
  • Resulting risk: Compromise of CI/CD or development environments.

Live Threat

Current exploitation, exposure, and threat context

A contributor could craft a pull request where the displayed code in Gitea's web interface appears safe, but the actual code checked out or used by CI/CD systems at the same commit contains malicious content. This could occur when Git trees contain duplicate file names, leading to inconsistent handling between Gitea's views and Git's checkout or actions processes.

  • Code integrity and execution.
  • Duplicate filenames in Git trees.
  • Malicious code execution in CI.

Operational Fix

Recommended remediation, mitigation, and detection steps

Gitea instance owners and the platform teams managing them are likely responsible for addressing this vulnerability. The immediate first step is to locate all Gitea instances, determine their exposure and criticality, and identify the responsible teams for remediation planning.

  • Own: Gitea instance owners/platform teams.
  • Verify: Instance reachability and business criticality.
  • Act: Plan remediation considering exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Gitea?

Gitea is an open-source, self-hosted Git service designed to manage code repositories. It provides developers with a web-based interface for hosting projects, facilitating team collaboration, managing pull requests, and integrating with CI/CD pipelines to automate testing and deployment workflows.

What is the nature of the vulnerability in CVE-2026-95106?

This is a path confusion issue, classified as CWE-706 (Use of Incorrect Resolver). It occurs because Gitea's web interface and underlying Git tools interpret duplicate filenames within a Git tree differently. This discrepancy allows a contributor to present safe-looking code in the web view while ensuring a separate, malicious version is used by automated systems or manual checkouts.

How does an attacker trigger this issue?

An attacker initiates the vulnerability by pushing a specially crafted Git tree that contains two entries with the same name. The bug is triggered when a user views the pull request in the web interface or when a downstream system, such as a CI/CD process or a local git checkout, processes that specific commit. It is important to note that incoming objects are now validated for consistency, but objects already present in existing repositories are not automatically scanned.

Do I need to worry if my Gitea instance is internal?

Halo Surface Signal indicates that Gitea is frequently deployed as an internet-facing application to support remote collaboration, which increases the likelihood of external interaction. While internet-facing instances face higher risk from unauthorized contributors, any environment where pull requests are processed—even internally—should evaluate their exposure to this content discrepancy.

What should I do first to manage this risk?

Begin by inventorying your organization to locate all running Gitea instances and identifying the teams responsible for their maintenance. Once identified, assess the business criticality and network exposure of each instance to prioritize your remediation planning. Focus on coordinating with platform teams to ensure that the necessary updates or consistency checks are implemented for your repositories.

References