CVE-2026-96400
N/A
N/A
Summary
With [migrations] ALLOWED_DOMAINS set to a matching entry such as * or a hostname wildcard, Gitea's migration URL validation could permit reserved and link-local addresses, such as 169.254.169.254, even when ALLOW_LOCALNETWORKS = false. The local-network block list did not cover these ranges, and a hostname matching the allow list was accepted regardless of its resolved address. A user who can start migrations on such an instance could reach these addresses from the Gitea server; the default empty ALLOWED_DOMAINS configuration is not affected.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Gitea | Gitea | 0 <= 1.27.3 | affected |
Weaknesses
- CWE-918: CWE-918: Server-Side Request Forgery (SSRF)
References
- https://github.com/go-gitea/gitea/security/advisories/GHSA-54w9-6cc5-9wj9
- https://github.com/go-gitea/gitea/pull/39426
- https://blog.gitea.com/release-of-28.0.0/
- https://github.com/go-gitea/gitea/releases/tag/v28.0.0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.