CVE-2026-96400

Summary

With [migrations] ALLOWED_DOMAINS set to a matching entry such as * or a hostname wildcard, Gitea's migration URL validation could permit reserved and link-local addresses, such as 169.254.169.254, even when ALLOW_LOCALNETWORKS = false. The local-network block list did not cover these ranges, and a hostname matching the allow list was accepted regardless of its resolved address. A user who can start migrations on such an instance could reach these addresses from the Gitea server; the default empty ALLOWED_DOMAINS configuration is not affected.

Affected Software

VendorProductVersion RangeStatus
GiteaGitea0 <= 1.27.3affected

Weaknesses

  • CWE-918: CWE-918: Server-Side Request Forgery (SSRF)

References