๐Ÿ” CVE Alert

CVE-2026-104636

UNKNOWN 0.0

Gitea SSRF through Git HTTP redirects in mirrors and fetches

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Gitea validated the initial remote URL for push mirrors, wiki remote checks, and fetches of migrated pull request heads, but the subsequent raw Git operations followed HTTP redirects without revalidating the destination. A repository administrator using a policy-allowed endpoint that redirects could make Gitea's Git client send requests to an address that the outbound host policy would otherwise block. The impact depends on the configured policy and the internal services reachable from the server.

CWE CWE-918
Vendor gitea
Product gitea
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for gitea gitea

Be the first to know when new unknown vulnerabilities affecting gitea gitea are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Gitea / Gitea
0 โ‰ค 1.27.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/go-gitea/gitea/security/advisories/GHSA-g4hw-fg4c-89mq github.com: https://github.com/go-gitea/gitea/pull/39426 blog.gitea.com: https://blog.gitea.com/release-of-28.0.0/ github.com: https://github.com/go-gitea/gitea/releases/tag/v28.0.0

Credits

๐Ÿ” https://github.com/ihopenre-eng ๐Ÿ” https://github.com/ElectQ https://github.com/TheFox0x7 https://github.com/silverwind https://github.com/bircni https://github.com/wxiaoguang