CVE-2026-101027

Summary

When [migrations] ALLOWED_DOMAINS was configured, a hostname matching the allow list was accepted without checking its resolved address against the local-network restrictions. A user who can start repository migrations and control the DNS of an allowed hostname could make it resolve to loopback or private addresses and bypass ALLOW_LOCALNETWORKS = false, reaching internal services from the Gitea server. Instances without ALLOWED_DOMAINS configured are not affected by this specific bypass.

Affected Software

VendorProductVersion RangeStatus
GiteaGitea0 <= 1.27.3affected

Weaknesses

References