Description
Gitea accepted pushed Git trees containing two entries with the same name, which Git's own consistency checks reject. Gitea's web views resolved such a path to the first entry, while `git checkout`, Gitea Actions, and release archives use the last. A contributor could open a pull request whose diff and file views show benign content while CI and checkouts at the same commit use different, attacker-controlled content. Incoming objects are now checked for consistency; objects already stored in existing repositories are not rescanned.
Published:
2026-10-06
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 06 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gitea accepted pushed Git trees containing two entries with the same name, which Git's own consistency checks reject. Gitea's web views resolved such a path to the first entry, while `git checkout`, Gitea Actions, and release archives use the last. A contributor could open a pull request whose diff and file views show benign content while CI and checkouts at the same commit use different, attacker-controlled content. Incoming objects are now checked for consistency; objects already stored in existing repositories are not rescanned. | |
| Title | Gitea review and execution mismatch through duplicate tree entries | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Gitea
Published:
Updated: 2026-10-06T19:23:57.452Z
Reserved: 2026-10-04T21:57:35.565Z
Link: CVE-2026-95106
No data.
Status : Received
Published: 2026-10-06T20:17:34.867
Modified: 2026-10-06T20:17:34.867
Link: CVE-2026-95106
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.