Server-Side Request Forgery Vulnerability in Gitea by Go Gitea
CVE-2026-58441

6.3MEDIUM

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-58441?

A server-side request forgery (SSRF) vulnerability exists in Gitea that could allow an attacker to manipulate the system into making unauthorized HTTP requests. This occurs through the unsanitized 'Head.CloneURL' parameter within the 'pull_request.yml' file during the restore-repo process, potentially exposing sensitive information or enabling further attacks if exploited.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

yoojoon2
.