SSRF Vulnerabilities in Gitea from Gitea
CVE-2026-58508

9.1CRITICAL

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-58508?

Gitea is impacted by two server-side request forgery (SSRF) vulnerabilities arising from improper handling of DNS requests during migration and mirroring processes. These vulnerabilities involve a lack of re-validation and are exploitable through DNS rebinding techniques, potentially allowing malicious actors to make unauthorized requests to internal services. Users are encouraged to upgrade to Gitea version 1.27.0 or later to mitigate risks associated with this security flaw.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AmerMrkaljevic
.