---
id: CVE-2026-89182
title: >-
  With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as
  private, but the post-receive hook still applied the `repo.private=false` push
  option to an empty repository created by push
summary: >-
  With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as
  private, but the post-receive hook still applied the `repo.private=false` push
  option to an empty repository created by push. Any user who can create
  repositorie…
severity: none
cwe:
  - CWE-863
vendor: Gitea
product: gitea.dev
affected:
  - gitea.dev >= 1.27.0 <= 28.0.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:17:07.690'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89182'
references:
  - url: 'https://blog.gitea.com/release-of-28.1.0/'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/pull/39501'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/pull/39507'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/releases/tag/v28.1.0'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/security/advisories/GHSA-fx95-gwfc-grgc'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T22:23:15.972Z'
---

## Overview

With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The default configuration is not affected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
