SSRF Vulnerabilities in Gitea from Gitea
CVE-2026-58508
Currently unrated
What is CVE-2026-58508?
Gitea is impacted by two server-side request forgery (SSRF) vulnerabilities arising from improper handling of DNS requests during migration and mirroring processes. These vulnerabilities involve a lack of re-validation and are exploitable through DNS rebinding techniques, potentially allowing malicious actors to make unauthorized requests to internal services. Users are encouraged to upgrade to Gitea version 1.27.0 or later to mitigate risks associated with this security flaw.
Affected Version(s)
Gitea Open Source Git Server 0 <= 1.26.4
